Unusual outbound traffic to unknown IP addresses (often in Russia or Eastern Europe).

IP address, hardware ID, location, and screenshots of your desktop.

New folders in %AppData% or %LocalAppData% with random 8-character names.

From a different, clean device , change all passwords (Email, Banking, Discord).

Once the user extracts the RAR file, the typical infection flow is: