Hacker News new | ask | show | jobs
by roadkillon101 2716 days ago
I'm more curious about how they hacked into the SEC database? Did they use an email trojan? Exploit an existing flaw or backdoor? If they did this via e-mail, who did they send the mail to?
4 comments

The SEC’s complaint alleges that Ieremenko circumvented EDGAR controls that require user authentication and then navigated within the EDGAR system.

Looks like a way to say “exfiltrating data from the endpoints”.

The good old email trojan continues to be all you need.
> The hackers used malicious software sent via email to SEC employees. Then, after planting the software on the SEC computers, they sent the information they were able to gather from the EDGAR system to servers in Lithuania, where they either used it or distributed the data to other criminals, Carpenito said.
This is covered in the story. They sent email to SEC employees.