Update README.md

This commit is contained in:
S3N4T0R
2025-07-27 17:31:05 -04:00
committed by GitHub
parent d936d27239
commit 06fec27902
+12 -2
View File
@@ -10,6 +10,9 @@ I relied on Security Affairs to figure out the details to make this: https://sec
<img width="640" height="360" alt="imageedit_2_7042384654" src="https://github.com/user-attachments/assets/d984834c-babb-4eeb-8f46-49aa62fa7817" />
Stardust Chollima Operations performed: https://apt.etda.or.th/cgi-bin/showcard.cgi?g=Subgroup%3A%20Bluenoroff%2C%20APT%2038%2C%20Stardust%20Chollima&n=1
The dropper used to deliver the malware is related to the PowerRatankba, a Microsoft Visual C#/ Basic .NET
compiled executable associated with Stardust Chollima APT. The dropper was used to download a PowerRatankba
PowerShell reconnaissance tool, the dropper displays a fake job application form while downloads and executes
@@ -21,10 +24,11 @@ The PowerRatankba sample used in the Chilean interbank attack, differently from
the C&C server on HTTPS, This latter code is registered as a service through the “sc create” command as,
the malware gain persistence by setting an autostart.
BushidoToken Threat Intel: https://blog.bushidotoken.net/2021/08/the-lazarus-heist-where-are-they-now.html
<img width="640" height="484" alt="SWIFTphish" src="https://github.com/user-attachments/assets/c06b2f3e-9112-46b7-bccf-9123ae58eb1b" />
<img width="640" height="486" alt="NK_PIRsV2" src="https://github.com/user-attachments/assets/719f42c1-320f-44b8-ab40-376f4a886fae" />
1. Social engineering technique: The attackers delivered the malware, according toFlashpoint a trusted Redbanc IT
professional clicked to apply to a job opening found on social media.
@@ -40,7 +44,9 @@ persistence by setting an autostart .
The output of the command is captured and sent back to the C2 server.
<img width="640" height="486" alt="NK_PIRsV2" src="https://github.com/user-attachments/assets/719f42c1-320f-44b8-ab40-376f4a886fae" />
<img width="640" height="484" alt="SWIFTphish" src="https://github.com/user-attachments/assets/c06b2f3e-9112-46b7-bccf-9123ae58eb1b" />
## The first stage (social engineering technique)
@@ -57,4 +63,8 @@ recruiter, the attacker used a lure of job offer to attract the attention and co
<img width="417" height="455" alt="pp" src="https://github.com/user-attachments/assets/03cde7e3-389b-4300-b3ad-f3918fc1df1d" />
## The second stage (Fake job application - Backdoor Downloader by base64)
This Stager is a graphical user interface (GUI) designed to look like a registration form for a fake company called "Global
Processing Center, LTD." However, in reality, it contains malicious code that executes a hidden PowerShell script when run.
The dropper downloads and executes PowerRatankba in the background by useing (Base64).