Hijacks the PC’s microphone and camera to record audio and video.
Look for the file path C:\Users\ToxicEye\rat.exe on your system.
Deploys keyloggers to record every keystroke. How the Attack Works Bot Creation: Attackers create a dedicated Telegram bot.
The bot token is embedded into the ToxicEye configuration and compiled into an executable (.exe).
Can delete, transfer, or encrypt files for ransom (AES-256 encryption).