From 4eb3d519c1d0125ca489a883e90234214f17d533 Mon Sep 17 00:00:00 2001 From: S3N4T0R <121706460+S3N4T0R-0X0@users.noreply.github.com> Date: Mon, 25 Aug 2025 16:32:29 -0400 Subject: [PATCH] Update README.md --- North Koreans APT/Ricochet Chollima/README.md | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/North Koreans APT/Ricochet Chollima/README.md b/North Koreans APT/Ricochet Chollima/README.md index 4c3a290..52db7c7 100644 --- a/North Koreans APT/Ricochet Chollima/README.md +++ b/North Koreans APT/Ricochet Chollima/README.md @@ -31,3 +31,14 @@ The attacker impersonated a North Korea-focused expert based in South Korea, and 6. Dropbox C2: Get Command and Control through payload uses the Dropbox API to upload data including command output to Dropbox. imageedit_3_2570117683 + +## The first stage (delivery technique) + +The attacker impersonated a North Korea-focused expert based in South Korea. The spear-phishing email employed the subject line “러시아 전장에 투입된 인민군 장병들에게.hwp” (To North Korean Soldiers Deployed to the Russian Battlefield.hwp), with an attachment carrying the identical file name. The attachment was crafted to mimic a Hangul (HWP) document by leveraging the HWP icon image commonly associated with Naver Mail, thereby increasing its credibility. The threat actor intentionally used this icon to make the file appear as a legitimate document; however, the embedded link redirected the victim to a Dropbox-hosted payload instead of delivering a benign file. The Dropbox URL ultimately provided a compressed archive containing additional malicious components. + +imageedit_1_7438116774 + +The decoy HWP document contains a letter addressed to North Korean soldiers deployed to Russia. + +imageedit_2_7840143710 +