Update README.md

This commit is contained in:
S3N4T0R
2024-12-29 11:24:08 -05:00
committed by GitHub
parent 7b9887d9e4
commit 129606fb82
+1 -1
View File
@@ -121,7 +121,7 @@ This payload is a malicious program that establishes a reverse shell to an attac
Uses Windows' Winsock API to set up the socket connection to the attacker.
## Final result: payload connect to OneDrive C2 server
## The fourth stage (Data Exfiltration) over OneDrive API C2 Channe
I have previously performed Data Exfiltration during an APT28 attack via OneDrive. You can refer to this link: https://github.com/S3N4T0R-0X0/APT-Attack-Simulation/tree/main/Russian%20APT/APT28-Adversary-Simulation for detailed steps on how this can be accomplished. However, in this particular attack, a more advanced and non-open-source version of BEAR-C2 was utilized for Data Exfiltration.