I'm not denying its effectiveness, just remarking on its technical merit as a topic of discussion. Once the system is already compromised it becomes less about the payload and more about the attack vector involved. If the payload in question was using novel techniques then it would be a different story but the analysis shows the program to be relatively rudimentary.