NetSupport RAT renamed hypersnap.exe hidden launch + logon task
Detects suspicious PowerShell activity involving compression commands (e.g., Expand-Archive) within APPDATA, correlated with the execution of hypersnap.exe with hidden window arguments, and the creation of persistence via scheduled tasks. This pattern is indicative of automated staging or malicious tool execution and persistence setup.
Microsoft Sentinel (KQL)

