exe application must be copied to an external thumb drive. Although, this is generic detection for Wacatac category Trojan threat. Other details can be found in Man-in-the-browser attack. Step 4: Isolate the Analysis VM and Disable Windows Defender AV.
Watch overview (3:05) The Microsoft Client Server Runtime Server subsystem utilizes the process csrss.
Trojan windows client GreaterFire released this on Mar 24, 2020.