← Back to context

Comment by nickphx

3 hours ago

They claim it was an ngrok account that was used to host an endpoint used in the compromise, tied to a microsoft account / gdid that was passed when ngrok software was downloaded from the "microsoft store".

That wouldn't explain how they connected the GDID to the visit to the retailers website

> Three hours later, the same GDID visited the retailer’s own website, through the same Tzulo proxy address used to set up the ngrok account.