Or alteast you think it does. The thing is as I said with a rooted box, after it's rooted you can never be sure there ain't no backdoor left. It doesn't need to regularly communicate with an external server, it can probably dump data at some odd dates so it's much harder to track. The thing is there is no damage control with a botnet client by design like Windows 10
Didn't I qualify my statement and choose words to castigate Microsoft? It's amazing to me that keylogging is now reduced to injecting something into hosts and decoding their protocol. The latter may be tricky but knowing MS security record, inevitable.