logoalt Hacker News

flexagoonyesterday at 9:01 PM0 repliesview on HN

AFAIK most malware like this first sends the contents of your environment variables, ssh keys, passwords, etc. to the server, and then sets up a persistent process that executes arbitrary commands received from the attacker's server at any time, allowing them to run whatever else they want