If anyone else is trying to do any #threathunting on this article, I have found several related incidents where the lnk file just runs a vbs script in the zip file instead, and some using msiexec instead of autoit. I've had success searching on copying curl from system32.
The search looks for a cmd.exe process with copy followed by a system32 path to an executable.
https://www.truesec.com/hub/blog/darkgate-loader-delivered-via-teams
Title: DarkGate Loader delivered via Teams - Truesec
Malspam campaigns involving DarkGate Loader have been on the rise since its author started advertising it as a Malware-as-a-Service offering on popular cybercrime forums in June 2023. Until now DarkGate Loader was seen delivered via traditional email malspam campaigns similar to those of Emotet. In August an operator started using Microsoft Teams to deliver the malware via HR themed social engineering chat messages.