✔️Copies itself to %APPDATA%\WindowsGraphics\win_gfx_driver.exe ✔️Hides the copied file (attributes +h +s) ✔️Adds itself to Windows startup (Run registry key) ✔️Steals passwords saved in Chrome, Edge, Brave, OperaGX ✔️Decrypts and collects login credentials from Chromium-based browsers ✔️Copies Firefox cookie databases ✔️Searches the user folder for documents (.txt, .pdf, .docx, .xlsx) up to ~10 MB ✔️Creates a ZIP archive with all stolen data ✔️Sends stolen data to the Discord webhook ✔️Sends periodic screenshots (every ~2 minutes) to another Discord webhook ✔️Takes special screenshots when the browser window title contains sensitive words (login, bank, steam, gmail, etc.) ✔️Runs a keylogger and sends keyboard logs every 60 seconds to Discord ✔️Mentions a specific user (@) in Discord messages when critical events occur ✔️Uses multiple Discord webhooks for logs, screenshots, and stolen data ✔️Runs most functions in background threads Performs basic cleanup after sending data (deletes temporary files/folders)