mirror of
https://github.com/S3N4T0R-0X0/APTs-Adversary-Simulation.git
synced 2026-08-04 09:41:40 +02:00
Update README.md
This commit is contained in:
@@ -6,4 +6,11 @@ This is a simulation of attack by (Mustang Panda) APT group targeting government
|
||||
|
||||
This attack included several stages including redirect to a Visual Studio Code web environment that is connected to the compromised machine. They are then permitted to execute commands and scripts, and to create new files on the infected machine, Stately Taurus used this technique to deliver malware to infected environments, perform reconnaissance and exfiltrate sensitive data. To establish constant access to the reverse shell, the attacker created persistence for a script named (startcode.bat) using a scheduled task that is responsible for starting the shell.
|
||||
|
||||
1. Use Visual Studio Code's reverse shell to execute arbitrary code and deliver additional payloads.
|
||||
|
||||

|
||||
|
||||
## The first stage (delivery technique)
|
||||
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user