From 05818aab55e578fffe0fa422bfb3ca18be4d5c3c Mon Sep 17 00:00:00 2001 From: S3N4T0R <121706460+S3N4T0R-0X0@users.noreply.github.com> Date: Thu, 7 Aug 2025 13:39:38 -0400 Subject: [PATCH] Update README.md --- North Koreans APT/Stardust Chollima/README.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/North Koreans APT/Stardust Chollima/README.md b/North Koreans APT/Stardust Chollima/README.md index a7806a4..20ecfb0 100644 --- a/North Koreans APT/Stardust Chollima/README.md +++ b/North Koreans APT/Stardust Chollima/README.md @@ -95,7 +95,8 @@ Breakdown of the Malicious Code Execution: This PowerShell script is a reverse shell with persistence, meaning it allows an attacker to gain remote access to the infected machine and ensures it runs every time the system starts. -Screenshot From 2025-07-27 18-12-05 +Screenshot From 2025-08-07 13-37-55 + Once connected: @@ -111,3 +112,4 @@ Every time the user logs in, the malicious script executes again, ensuring the a +