BotHelper ClipperStart/ClipperStop clipboard-hijack command tasking

Detects the BotHelper RAT utilizing its msedge_proxy.exe process to execute 'ClipperStart' or 'ClipperStop' commands. These commands are indicative of the malware's clipboard-address substitution functionality, which is used to redirect cryptocurrency transactions by modifying clipboard content.