TonRAT Run Key Persistence via node.exe bun.exe wscript.exe or cscript.exe
Detects the TonRAT malware establishing persistence by modifying Windows Run or RunOnce registry keys. The rule specifically monitors for registry value creation or modification triggered by scripting or runtime host processes such as node.exe, bun.exe, wscript.exe, or cscript.exe, when the referenced persistence path points to locations commonly used for malicious payloads, such as AppData, ProgramData, or Temp directories, or involves JavaScript files.
Sigma

