TonRAT Portable node.exe Execution from User-Writable Non-Standard Directory
Detects the execution of node.exe from common user-writable or non-standard directories such as AppData, Downloads, Temp, ProgramData, or Desktop, accompanied by JavaScript file arguments. This behavior is indicative of the TonRAT campaign which uses a portable Node.js runtime to execute malicious JavaScript payloads in a stealthy manner, bypassing standard installation path detection.
Sigma

