It’s even mentioning they are detecting the agent framework so it’s easy to hide the malware inside its config/work directory. It’s clear, the best way to mitigate that is to start using per project scoped sandboxes.
Egress was the channel (DNS/OAST callbacks) so the network limitations beats the app layer boundaries.