Hacker News new | ask | show | jobs
by nickphx 4 days ago
They claim it was an ngrok account that was used to host an endpoint used in the compromise, tied to a microsoft account / gdid that was passed when ngrok software was downloaded from the "microsoft store".
1 comments

That wouldn't explain how they connected the GDID to the visit to the retailers website

> Three hours later, the same GDID visited the retailer’s own website, through the same Tzulo proxy address used to set up the ngrok account.