Update README.md

This commit is contained in:
S3N4T0R
2024-12-29 11:24:08 -05:00
committed by GitHub
parent 7b9887d9e4
commit 129606fb82
+1 -1
View File
@@ -121,7 +121,7 @@ This payload is a malicious program that establishes a reverse shell to an attac
Uses Windows' Winsock API to set up the socket connection to the attacker. Uses Windows' Winsock API to set up the socket connection to the attacker.
## Final result: payload connect to OneDrive C2 server ## The fourth stage (Data Exfiltration) over OneDrive API C2 Channe
I have previously performed Data Exfiltration during an APT28 attack via OneDrive. You can refer to this link: https://github.com/S3N4T0R-0X0/APT-Attack-Simulation/tree/main/Russian%20APT/APT28-Adversary-Simulation for detailed steps on how this can be accomplished. However, in this particular attack, a more advanced and non-open-source version of BEAR-C2 was utilized for Data Exfiltration. I have previously performed Data Exfiltration during an APT28 attack via OneDrive. You can refer to this link: https://github.com/S3N4T0R-0X0/APT-Attack-Simulation/tree/main/Russian%20APT/APT28-Adversary-Simulation for detailed steps on how this can be accomplished. However, in this particular attack, a more advanced and non-open-source version of BEAR-C2 was utilized for Data Exfiltration.