SloppyRAT Persistence via Run Key or COM Hijack InprocServer32
Detects two distinct methods used for persistence and execution: 1) Addition of 'rundll32' to Windows Registry Run keys, often used to execute malicious code upon logon. 2) Creation or modification of COM InprocServer32 registry keys, a technique known as COM Hijacking used to load malicious DLLs when a legitimate COM object is initialized.
SentinelOne

