logoalt Hacker News

nickphxtoday at 5:31 PM1 replyview on HN

They claim it was an ngrok account that was used to host an endpoint used in the compromise, tied to a microsoft account / gdid that was passed when ngrok software was downloaded from the "microsoft store".


Replies

sorenjantoday at 5:44 PM

That wouldn't explain how they connected the GDID to the visit to the retailers website

> Three hours later, the same GDID visited the retailer’s own website, through the same Tzulo proxy address used to set up the ngrok account.