From 67010fe80d7df1ce6023980f229ae3df7c379879 Mon Sep 17 00:00:00 2001 From: S3N4T0R <121706460+S3N4T0R-0X0@users.noreply.github.com> Date: Sun, 6 Jul 2025 08:13:11 +0300 Subject: [PATCH] Add files via upload --- North Koreans APT/Famous Chollima/README.md | 5 +++++ 1 file changed, 5 insertions(+) create mode 100644 North Koreans APT/Famous Chollima/README.md diff --git a/North Koreans APT/Famous Chollima/README.md b/North Koreans APT/Famous Chollima/README.md new file mode 100644 index 0000000..7158543 --- /dev/null +++ b/North Koreans APT/Famous Chollima/README.md @@ -0,0 +1,5 @@ +# Famous Chollima APT Adversary Simulation + +This is a simulation of attack by (Famous Chollima) APT group targeting job seekers to accomplish their goals and wide variety of United States (US) companies, the attack campaign was active early as December 2022, The attack chain starts with attackers invites the victim to participate in an online interview. The attackers likely uses video conferencing or other online collaboration tools for the interview. During the interview, the attackers convinces the victim to download and install an NPM-based package hosted on GitHub. The threat actor likely presents the package to the victim as software to review or analyze, but it actually contains malicious JavaScript designed to infect the victim’s host with backdoor malware. I relied on paloalto unit42 to figure out the details to make this https://unit42.paloaltonetworks.com/two-campaigns-by-north-korea-bad-actors-target-job-hunters/ + +