⚠️ Full list of observed C2 commands:
🔹 Privilege-related functions and persistence mechanisms: uac_bypass, rootkit_enable, rootkit_disable, watchdog_status, protection_config, uxlocker_trigger, voltage_drop
🔹 Data theft and credential harvesting: stealer, steam, keylogger_logs, clipboard_history, file_download
🔹 Process control and command execution: process_list, process_kill, cmd
🔹 File upload and execution: file_upload, file_run, file_execute, file_delete, mkdir, file_list, explorer_restart
🔹 Screen capture and streaming: screenshot, monitors_list, screen_stream_start, screen_stream_stop
🔹 Webcam and microphone access: webcam_list, webcam_capture, microphone_record
🔹 Keylogging and clipboard monitoring: keylogger_start, keylogger_stop, keylogger_logs, input, clipboard_monitor_start, clipboard_monitor_stop, clipboard_history, clipper_get_addresses, clipper_set_address
🔹 C2 session management and keepalive: ping, pong, client_hello, connected
🔹 Update and removal functions: update, uninstall
🔹 User disruption and system manipulation: fun, fun_message, fun_wallpaper, fun_openurl, fun_shake, fun_sound, fun_restart, fun_shutdown, fun_bsod