From 0a1e58e28f7a37b498845b8a1c808d18d77a61b1 Mon Sep 17 00:00:00 2001 From: S3N4T0R <121706460+S3N4T0R-0X0@users.noreply.github.com> Date: Fri, 14 Feb 2025 15:32:08 -0500 Subject: [PATCH] Update README.md --- North Koreans APT/Velvet Chollima/README.md | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/North Koreans APT/Velvet Chollima/README.md b/North Koreans APT/Velvet Chollima/README.md index 9c0db20..c464a25 100644 --- a/North Koreans APT/Velvet Chollima/README.md +++ b/North Koreans APT/Velvet Chollima/README.md @@ -14,3 +14,10 @@ https://www.bleepingcomputer.com/news/security/fake-google-meet-conference-error ![dialogs](https://github.com/user-attachments/assets/9d5a1b31-5479-4a67-826c-68195fb2c3a5) + + +1. social engineering: Create PDF file which will be sent spear-phishing. + +2. ClickFix technique: (Fake-Captcha) to make the target run PowerShell as an administrator and paste attacker-provided code. + +3.reverse shell: Make simple reverse shell payload to creates a TCP connection to a command and control (C2) server.