Abyssos HVNC cookie theft with correlated port 9222 debugging injection

Detects the Abyssos HVNC_CLONE_START to GRABCOOKIES to cookie-injection chain: browser profile/cookie staging under a temp fontconfigs folder correlated with a non-browser process connecting to a local Chrome/Edge/Brave remote-debugging port (9222) used for Network.setCookie session hijacking.