mirror of
https://github.com/S3N4T0R-0X0/APTs-Adversary-Simulation.git
synced 2026-08-04 09:41:40 +02:00
Update README.md
This commit is contained in:
@@ -31,3 +31,14 @@ The attacker impersonated a North Korea-focused expert based in South Korea, and
|
||||
6. Dropbox C2: Get Command and Control through payload uses the Dropbox API to upload data including command output to Dropbox.
|
||||
|
||||
<img width="702" height="354" alt="imageedit_3_2570117683" src="https://github.com/user-attachments/assets/cf10354c-b377-4baf-b217-76f01b353f15" />
|
||||
|
||||
## The first stage (delivery technique)
|
||||
|
||||
The attacker impersonated a North Korea-focused expert based in South Korea. The spear-phishing email employed the subject line “러시아 전장에 투입된 인민군 장병들에게.hwp” (To North Korean Soldiers Deployed to the Russian Battlefield.hwp), with an attachment carrying the identical file name. The attachment was crafted to mimic a Hangul (HWP) document by leveraging the HWP icon image commonly associated with Naver Mail, thereby increasing its credibility. The threat actor intentionally used this icon to make the file appear as a legitimate document; however, the embedded link redirected the victim to a Dropbox-hosted payload instead of delivering a benign file. The Dropbox URL ultimately provided a compressed archive containing additional malicious components.
|
||||
|
||||
<img width="620" height="449" alt="imageedit_1_7438116774" src="https://github.com/user-attachments/assets/39b0c384-16af-4405-9281-6c73642ba74b" />
|
||||
|
||||
The decoy HWP document contains a letter addressed to North Korean soldiers deployed to Russia.
|
||||
|
||||
<img width="586" height="714" alt="imageedit_2_7840143710" src="https://github.com/user-attachments/assets/928315fd-596a-4906-9024-4a2b1017e974" />
|
||||
|
||||
|
||||
Reference in New Issue
Block a user