Python Embed runtime abused to launch disguised .cat backdoor payload
Detects the execution of Python interpreters from non-standard, user-writable directories (such as Public\Music) or using suspicious filenames. This behavior is indicative of threat actors abusing the Python Embeddable package to run disguised Python backdoors, such as the Chinotto malware family observed in APT37 operations, often staged via batch scripts or curl.
Sigma

