From 0118a568df7a79de32a0d7225abb9b90c1eb8d8a Mon Sep 17 00:00:00 2001 From: S3N4T0R <121706460+S3N4T0R-0X0@users.noreply.github.com> Date: Wed, 1 Jan 2025 02:52:42 -0500 Subject: [PATCH] Update README.md --- Chinese APT/Wicked Panda/README.md | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/Chinese APT/Wicked Panda/README.md b/Chinese APT/Wicked Panda/README.md index b3ccd83..452ef9b 100644 --- a/Chinese APT/Wicked Panda/README.md +++ b/Chinese APT/Wicked Panda/README.md @@ -128,12 +128,17 @@ I have previously performed Data Exfiltration during an Gossamer-Bear-APT attack The attackers used the Google Drive C2 (Command and Control) API as a means to establish a communication channel between their payload and the attacker's server, By using Google Drive as a C2 server, attackers can hide their malicious activities among the legitimate traffic to OneDrive, making it harder for security teams to detect the threat. First i need to create a google Drive account, as shown in the following figure 1.Log into the Google Cloud Platform + 2.Create a project in Google Cloud Platform dashboard + 3.Enable Google Drive API + 4.Create a Google Drive API key + ![337354597-b90e328c-5184-4072-adcb-6a6d7fb2debd](https://github.com/user-attachments/assets/8c63b7b4-6458-45ba-8715-374d471906dc) + I used the GoogleDrive C2 (Command and Control) API as a means to establish a communication channel between the payload and the attacker's server, By using GoogleDrive as a C2 server, i can hide the malicious activities among the legitimate traffic to GoogleDrive, making it harder for security teams to detect the threat. ![Screenshot From 2025-01-01 02-48-44](https://github.com/user-attachments/assets/0d47a318-c0c2-4846-b272-9ee30395b2c8)