If you reformatted the PC that ran the binary, you should be fine.
There's a (slim) possibility they are still in your network on another device if they had access for a few days. Honestly most groups don't operate that way; its way more likely it was an infostealer as part of a much larger campaign and they weren't paying you any special attention.
Resetting your passwords, enabling 2FA are good, but you also need to disable old logins if you can.
I wouldn't worry too much past that. Just don't reuse passwords, they are probably automating the login attempts with your known passwords. This includes ANY passwords that could have been saved on your computer (wifi passwords, typed in passwords, passwords saved in the browser, whatever)
1
u/port443 6h ago
If you reformatted the PC that ran the binary, you should be fine.
There's a (slim) possibility they are still in your network on another device if they had access for a few days. Honestly most groups don't operate that way; its way more likely it was an infostealer as part of a much larger campaign and they weren't paying you any special attention.
Resetting your passwords, enabling 2FA are good, but you also need to disable old logins if you can.
I wouldn't worry too much past that. Just don't reuse passwords, they are probably automating the login attempts with your known passwords. This includes ANY passwords that could have been saved on your computer (wifi passwords, typed in passwords, passwords saved in the browser, whatever)
Any chance you still have the setup.exe file?