Hacker News new | ask | show | jobs
by enkid 2134 days ago
They have the server software. There's a couple ways they could get it. 1.) They could have hacked the C2 server or a development network, like you are talking about. 2.) The server could be forward deployed to a cloud provider or other infrastructure and law enforcement served a subpoena for a copy of the cloud server. The second seems just as likely as the first.
1 comments

Or they could have just bought a copy from a compromised developer. Real world spying happens a lot too.
Yeah, there's a lot of other ways they could have gotten it.