The employee changed his Microsoft 365 password twice.
The attacker still logged back in.
That was the moment we knew we were not dealing with a normal stolen-password incident.
The first alert came from an impossible-travel sign-in. The employee had authenticated from Maryland, then the same account appeared from another country less than an hour later.
We reset the password.
Twenty minutes later, another suspicious session appeared.
So we reset it again and forced MFA re-registration.
The attacker came back.
At that point, I stopped looking at the account and started looking at the employee’s laptop.
Inside the Downloads folder was a file called:
Invoice_Viewer.exe
The employee remembered downloading it from a website that claimed he needed a special viewer to open an invoice.
Windows logs showed the file running at 9:14 AM.
Seconds later, it launched PowerShell in the background.
Then we found something else.
A scheduled task called MicrosoftEdgeUpdateCheck had been created on the machine.
The name looked legitimate enough to ignore if you were moving quickly, but it was not one of Microsoft Edge’s normal update tasks.
We also found an outbound HTTPS connection from the compromised host to an external IP address.
The file hash was submitted for malware analysis.
It came back as an information stealer.
That explained why changing the password had not solved the problem.
The malware had stolen browser data, including authentication cookies and active session information.
The attacker was not repeatedly discovering the employee’s new password.
They were reusing a session that had already been authenticated.
We revoked every active Microsoft 365 session, isolated the laptop from the network, removed the persistence, reset the credentials again, and rebuilt the endpoint.
The suspicious logins finally stopped.
A compromised account does not always mean the attacker still knows your password.
Sometimes you already changed the password.
The attacker is still inside because they stole the session.
I think Governor Sanwo-Olu needs to call Ganiyu Obasa Chairman of Agege Local Government to order. His projects are getting too much!!! What’s his plan gangan??? Dem no Dey do politics like this now. He just dey work dey go like Julius berger. Make he dey rest oooo 😂😂😂
@akinalabi Lol... Best of luck Olóyè🤞. I remember one of tweet like that some years ago which says "If you fail to learn that skill or take that course of 5yrs because you are getting old; in 5yrs time you'll still attain that age without that skill/degree". 😊
Corporate life will teach you that knowing the job is only half the battle.
The real skill is staying calm in meetings, reading the room, managing ego, receiving vague feedback, and not replying emails with your real thoughts.
4 years ago, @temmiloluwa_ and i found an extremely low-hanging critical flaw in a leading HMO’s web app that exposed clients’ records and health information.
we made multiple attempts to contact them, even reached out to their IT manager, but got no response.
Whatever amount you spend on any woman or provisions you make for her is not an investment of loyalty, faithfulness and eternal submission. Just do it because God commands you to do it. Have zero expectations and you will never be disappointed.
INCIDENT REPORT @PoliceNG@BenHundeyin@officialnyscng
On Saturday, 28th February, at about 10 AM, my girlfriend and I were on our way to Epe from Ikeja when we were stopped by officers from Ladegboye Police Station, Along Ijede Road, Ikorodu.