From 0e266b3818bd834aae1c1197f7ce0c096b69f244 Mon Sep 17 00:00:00 2001 From: S3N4T0R <121706460+S3N4T0R-0X0@users.noreply.github.com> Date: Thu, 19 Sep 2024 10:23:58 -0400 Subject: [PATCH] Update README.md --- North Koreans APT/Labyrinth Chollima/README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/North Koreans APT/Labyrinth Chollima/README.md b/North Koreans APT/Labyrinth Chollima/README.md index c2f7d9e..1a43896 100644 --- a/North Koreans APT/Labyrinth Chollima/README.md +++ b/North Koreans APT/Labyrinth Chollima/README.md @@ -1,6 +1,6 @@ # Labyrinth Chollima APT Adversary Simulation This is a simulation of attack by (Labyrinth Chollima) APT group targeting victims working on energy company and the aerospace industry, -the attack campaign was active before June 2024, The attack chain starts with +the attack campaign was active before June 2024, The attack chain starts with relies on legitimate job description content to target victims employed in U.S. critical infrastructure verticals. The job description is delivered to the victim in a password-protected ZIP archive containing an encrypted PDF file and a modified version of an open-source PDF viewer application, I relied on Mandiant to figure out the details to make this simulation: https://cloud.google.com/blog/topics/threat-intelligence/unc2970-backdoor-trojanized-pdf-reader/?linkId=10998021 ![imageedit_3_4780888868](https://github.com/user-attachments/assets/50214b93-9f5c-40ed-a31e-50aaacf448cc)