A recent incident revealed how a threat actor accidentally exposed its entire operational workflow by installing an endpoint detection and response (EDR) agent on its attack infrastructure .

Huntress analysts spotted the activity and were able to see many of the attacker's actions.
Initial observations of system activity and browsing history indicated sophisticated reconnaissance efforts, prompting researchers to delve deeper into the artifacts collected by the EDR system. Within hours of deployment, the agent recorded a series of interactions that indicated malicious intent. Huntress analysts noted that the machine identifier had appeared in previous breach investigations.
See also: Powerful DDoS attack targets DDoS scrubbing provider
Subsequent correlation of authentication logs and telemetry data revealed patterns of credential theft, session token refreshes, and execution of automated tools. Researchers detected attempts to access rotated session tokens and found evidence of automated phishing campaigns organized through special scripts.
The impact of this accidental installation of an EDR solution on an attacker’s infrastructure cannot be underestimated. For the first time, defenders gained detailed visibility into the daily routines of a threat actor, monitoring all of his actions.
EDR solution revealed the activities of a cybercriminal
The attacker's day typically began with passive external scanning and continued with targeted exploitation of organizations. Detailed browsing history records showed extensive use of both public and subscription services for reconnaissance, as well as the deployment of residential proxy services to anonymize traffic and avoid detection.

Over a three-month period, EDR telemetry captured a clear evolution in the attacker’s workflow. Early activities focused on investigating banking institutions and third-party vendors, while later stages revealed the adoption of automated workflows to create phishing messages.
See also: Jaguar Land Rover: Cyberattack led to data theft
Huntress researchers identified a gradual shift towards the use of more programmatic tools, with the adversary scheduling repetitive tasks to increase operational efficiency.
A deeper look into the infection mechanism reveals how the threat actor gained initial access and maintained a foothold within the target environments. The adversary exploited stolen session cookies extracted from Telegram Desktop cookie files using a simple Python script. This reveals how the attacker automated the extraction of primary refresh tokens for Microsoft Entra and Office 365 services
After obtaining valid tokens, the attacker was able to log into victim accounts without enabling multi-factor authentication or alerting endpoint defenses.
As for Persistence, it was achieved by developing scheduled tasks that regularly renewed session tokens and ran reconnaissance scripts. These tasks were registered in the Windows Task Scheduler, with “innocent” names, to be integrated into legitimate processes.
Huntress analysts identified these entries and observed periodic outbound connections to C2 servers controlled by the attacker (confirming ongoing control).
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: CISO: Human-centric cybersecurity is gaining ground

This rare visibility into the behavior of real threat actors provided invaluable insights for defenders. By analyzing infection and persistence techniques, security teams can create targeted detection rules and strengthen authentication workflows against similar attacks.
This incident of the accidentally installed EDR agent offers a rare glimpse behind the scenes of cybercrime. For the first time, analysts were able to observe in real time the daily routine of a hacker, from reconnaissance techniques to the automation of phishing campaigns. While this may help network defenders implement more effective security measures, the activities of this hacker show that cybercriminals operate with the operational discipline and tools of a regular company—just for the purpose of crime.
