New startup entries in HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run .
Attackers typically use social engineering to trick users into downloading the .rar file:
Includes "childish" features like hiding the taskbar, turning the monitor off, or moving the mouse to harass victims. 2. Common Infection Methods
Masquerading as urgent purchase orders or invoices that contain a malicious link or attachment.