@mir @yukarihinata If I look at what was running on the machine, that was the pretty obvious choice. They said "passwordless sudo on the pleroma account" and it lines up; they could have been lying, who knows? They tried (failed) to wipe the auth logs so you can see when the exfil happened and which account did it, they have a lot of clanker-looking shit in the history (pasted commands that had `[ip]` in it and then the following command had the actual IP), there was a .keep.o and that is a claude habit, which is probably why they did dumb shit like trying to wipe the logs after they were done instead of turning off logging. (There's no substitute for knowing what you're doing.)