file_path

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\svchost

discovered 2026-06-01

Registry Run key set by Epsilon Stealer for boot persistence. Points to %LOCALAPPDATA%\Microsoft\Windows\0\svchost.exe.