From 129606fb8295cbde9011af605b2596cac6fe95b5 Mon Sep 17 00:00:00 2001 From: S3N4T0R <121706460+S3N4T0R-0X0@users.noreply.github.com> Date: Sun, 29 Dec 2024 11:24:08 -0500 Subject: [PATCH] Update README.md --- Chinese APT/Wicked Panda/README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Chinese APT/Wicked Panda/README.md b/Chinese APT/Wicked Panda/README.md index d261445..d4242af 100644 --- a/Chinese APT/Wicked Panda/README.md +++ b/Chinese APT/Wicked Panda/README.md @@ -121,7 +121,7 @@ This payload is a malicious program that establishes a reverse shell to an attac Uses Windows' Winsock API to set up the socket connection to the attacker. -## Final result: payload connect to OneDrive C2 server +## The fourth stage (Data Exfiltration) over OneDrive API C2 Channe I have previously performed Data Exfiltration during an APT28 attack via OneDrive. You can refer to this link: https://github.com/S3N4T0R-0X0/APT-Attack-Simulation/tree/main/Russian%20APT/APT28-Adversary-Simulation for detailed steps on how this can be accomplished. However, in this particular attack, a more advanced and non-open-source version of BEAR-C2 was utilized for Data Exfiltration.