Unexpected outbound network connections to unknown IP addresses.
May modify autorun registry keys to ensure it launches every time the computer restarts. 3. Network Activity (C2)
I can provide more specific details if you have a of your specific sample or if you'd like to see a list of common file paths it uses for persistence. Would you like a list of detection rules (like Sigma or Yara) for this threat? New Families and Detection Updates - Hatching Triage
Specifically targets browser-stored credentials and messaging client data, such as Discord tokens.