From 336e9f57bb1acff1e275ffec79dd5701f38ea273 Mon Sep 17 00:00:00 2001 From: S3N4T0R <121706460+S3N4T0R-0X0@users.noreply.github.com> Date: Sun, 3 May 2026 06:24:31 -0400 Subject: [PATCH] Update README.md --- Iranian APT/Charming Kitten/README.md | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/Iranian APT/Charming Kitten/README.md b/Iranian APT/Charming Kitten/README.md index e7d6801..7c5cf1d 100644 --- a/Iranian APT/Charming Kitten/README.md +++ b/Iranian APT/Charming Kitten/README.md @@ -25,4 +25,7 @@ The infected document included specific references to “Engineering, Constructi In this campaign, the blurred document lure delivers a new payload as a custom HTTP backdoor. -To maintain persistence, the group has evolved its development approach by leveraging AI-generated code and Rust-based tools, such as the BlackBeard backdoor, to rapidly deploy custom implants. Additionally, the group uses standard HTTP status codes, customized UDP based traffic, and the Telegram API for C2 communications. +To maintain persistence, the group has evolved its development approach by leveraging AI-generated code and Rust-based tools, such as the BlackBeard backdoor, to rapidly deploy custom implants. Additionally, the group uses standard HTTP status codes, customized UDP based traffic, and the Telegram API for C2 communications. + +word-image-379309-175304-15-1536x198 +