The final-stage payload is a complex backdoor equipped with comprehensive command execution, arbitrary file upload/download, host reconnaissance, payload staging, and lateral movement capabilities. It persists by injecting malicious code into common enterprise collaboration applications like DingTalk, Wukong, and Qoder.