mirror of
https://github.com/S3N4T0R-0X0/APTs-Adversary-Simulation.git
synced 2026-08-04 09:41:40 +02:00
Update README.md
This commit is contained in:
@@ -1,7 +1,6 @@
|
||||
# Labyrinth Chollima APT Adversary Simulation
|
||||
|
||||
This is a simulation of attack by (Labyrinth Chollima) APT group targeting victims working on energy company and the aerospace industry,
|
||||
the attack campaign was active before June 2024, The attack chain starts with relies on legitimate job description content to target victims employed in U.S. critical infrastructure verticals. The job description is delivered to the victim in a password-protected ZIP archive containing an encrypted PDF file and a modified version of an open-source PDF viewer application, I relied on Mandiant to figure out the details to make this simulation: https://cloud.google.com/blog/topics/threat-intelligence/unc2970-backdoor-trojanized-pdf-reader/?linkId=10998021
|
||||
This is a simulation of attack by (Labyrinth Chollima) APT group targeting victims working on energy company and the aerospace industry, the attack campaign was active before June 2024, The attack chain starts with relies on legitimate job description content to target victims employed in U.S. critical infrastructure verticals. The job description is delivered to the victim in a password-protected ZIP archive containing an encrypted PDF file and a modified version of an open-source PDF viewer application, I relied on Mandiant to figure out the details to make this simulation: https://cloud.google.com/blog/topics/threat-intelligence/unc2970-backdoor-trojanized-pdf-reader/?linkId=10998021
|
||||
|
||||

|
||||
|
||||
@@ -14,4 +13,6 @@ When accessed this way, the DLL files are loaded by the SumatraPDF.exe executabl
|
||||
|
||||

|
||||
|
||||
1.Create job description PDF file which will be sent spear phishing.
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user