https://securelist.com/goffee-apt-new-attacks/116139/


an HTA and a PowerShell file, and writes the HTA into the registry using the...