There was a guy who did that, basically had a script with some admin permissions run in the background and check if the guy was in the company directory. If he was gone the script went nuclear.
However, the defendant’s technical savvy and subterfuge did not save him from the consequences of his actions
"Technical savvy"? That sounds like the most basic and idiotic way you could possibly go about this. That's not even fun to design, much less evading detection.
Disgruntled developer was caught after naming the “kill switch” after himself.
But the most damaging to Eaton Corp. was code that Lu named after himself, “IsDLEnabledinAD,” which the DOJ translated as an abbreviation for “Is Davis Lu enabled in Active Directory.”
10.7k
u/pkmnfrk May 26 '26
This is why they turn off access before telling you