I thought they got access through an update sever with a weak password?
Was the attack otherwise sophisticated and just relied on an easy entry point? So the breaking in was easy, but the plan to steal once inside was sophisticated?
Was the attack otherwise sophisticated and just relied on an easy entry point? So the breaking in was easy, but the plan to steal once inside was sophisticated?
https://www.sec.gov/Archives/edgar/data/0001739942/000162828...
The amount of effort and different techniques they've put in to remain undetected for months (years?) while infecting a lot of actors is pretty impressive.