From 15e72e167ffce676c6377fb871fa60337bae3f13 Mon Sep 17 00:00:00 2001 From: S3N4T0R <121706460+S3N4T0R-0X0@users.noreply.github.com> Date: Thu, 7 Aug 2025 14:21:24 -0400 Subject: [PATCH] Update README.md --- North Koreans APT/Famous Chollima/README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/North Koreans APT/Famous Chollima/README.md b/North Koreans APT/Famous Chollima/README.md index d3a24eb..854132c 100644 --- a/North Koreans APT/Famous Chollima/README.md +++ b/North Koreans APT/Famous Chollima/README.md @@ -127,7 +127,6 @@ It's important to ensure that the payload file has the same name as defined insi ![IMG_20250706_113049_180](https://github.com/user-attachments/assets/1f89cf15-055d-4e82-93aa-0e267874ca81) -## The sixth stage (payload connect to TCP-C2 Server with XOR key) The final result is the successful establishment of a Command and Control channel. This is achieved by delivering a phishing link that mimics Microsoft login pages using BEAR-C2’s phishing module combined with an obfuscated JavaScript payload. Once executed, the payload initiates a reverse TCP connection to the attacker’s server, encrypted with XOR, allowing secure data exfiltration and remote command execution. @@ -141,3 +140,4 @@ https://github.com/user-attachments/assets/29d59e74-cdf5-464a-bd0d-8a151a9d762e +