file_path

%LOCALAPPDATA%\Microsoft\Windows\0\svchost.exe

discovered 2026-06-01

Epsilon Stealer persistence copy. Binary copied here and launched via HKCU Run key on reboot.