Sauron Loader (rnpkeys.exe/rnp.dll) Spawning Staged TEMP Payload Handlers
Detects the execution of various system binaries (e.g., rundll32.exe, powershell.exe, regsvr32.exe) launched from a Temp directory where the parent or actor process is identified as rnpkeys.exe or rnp.dll. This behavior is indicative of potential malicious activity where legitimate tools or utilities (GnuPG/RNP) are being abused to proxy the execution of secondary payloads or scripts.
Cortex XDR

