Profero IRT pulled apart "WindowsAudit.exe", a 101MB .NET RAT running as LocalSystem that uses a Discord guild as its primary C2.
Two channels inside one guild: one for tasking, one for results. Operators issue slash commands to target agents by hostname, Machine GUID, or broadcast to all. MQTT and Telegram sit as fallbacks.
Inside the kit: LSASS dumps, DPAPI browser theft, full AD takeover toolkit, Hell's Gate syscalls, AMSI/ETW patches, EDR kill for 15 vendors, WireGuard relay for pivoting.
This isn't a script-kiddie RAT. Looks like a ransomware crew warming up.