• After gaining access, the attackers had installed reverse SSH tools to create persistent outbound connections. This allowed them to maintain remote access while potentially avoiding defenses focused on blocking unsolicited inbound traffic.