submitted 8 months ago* (last edited 8 months ago) by to c/technology@lemmy.world
you are viewing a single comment's thread
view the rest of the comments
[–] 5 points 8 months ago

Maybe it was used as some sort of privilege escalation? E.g. NP++ downloads an XML file to %TEMP%, some already present malware modifies it, then GUP downloads a payload and executes it with administrator permissions.

  • source
  • parent