From 4b44693a77435f4215b7ebef91403c37036da29c Mon Sep 17 00:00:00 2001 From: S3N4T0R <121706460+S3N4T0R-0X0@users.noreply.github.com> Date: Sun, 27 Jul 2025 18:20:14 -0400 Subject: [PATCH] Update README.md --- North Koreans APT/Stardust Chollima/README.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/North Koreans APT/Stardust Chollima/README.md b/North Koreans APT/Stardust Chollima/README.md index b4aecda..00b0acd 100644 --- a/North Koreans APT/Stardust Chollima/README.md +++ b/North Koreans APT/Stardust Chollima/README.md @@ -55,12 +55,13 @@ The attackers delivered the malware, according to Flashpoint a trusted Redbanc I opening found on social media.The person that published the job opening then contacted the employee via linkedin Skype, etc for an interview and tricked him into installing the malicious code. -ss +Screenshot From 2025-07-27 18-18-16 + + The group addressed several employees of the company through LinkedIn's messaging. Passing himself as a Meta recruiter, the attacker used a lure of job offer to attract the attention and confidence of the target -pp ## The second stage (Fake job application - Backdoor Downloader by base64)