From 7a4891a791416abd0391620cea7110b331a734f0 Mon Sep 17 00:00:00 2001 From: S3N4T0R <121706460+S3N4T0R-0X0@users.noreply.github.com> Date: Sun, 6 Jul 2025 04:45:02 -0400 Subject: [PATCH] Update README.md --- North Koreans APT/Famous Chollima/README.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/North Koreans APT/Famous Chollima/README.md b/North Koreans APT/Famous Chollima/README.md index 1310f96..13ef08b 100644 --- a/North Koreans APT/Famous Chollima/README.md +++ b/North Koreans APT/Famous Chollima/README.md @@ -45,6 +45,9 @@ The attackers lure their victims by inviting them to job interviews. In other ca The attackers took advantage of the fact that their victims were part of the software development and IT community, possessing technical expertise and regularly working with GitHub. At the same time, using an open source project during a technical interview doesn’t seem unusual. Asking the victim to share their screen and test some code to assess their technical skills appeared to be a reasonable and clever tactic, especially when targeting victims from the IT field. +![Screenshot From 2025-07-06 04-26-33](https://github.com/user-attachments/assets/95ddb76e-6a1c-4369-a3f2-89a2fe8c4ae2) + + However, in some of the repositories created by the attackers, they forgot to disable comments on the project. As a result, some users and security researchers discovered the malicious technique and left comments on the repository warning that it contained malware and should not be used. This mistake was not identified early enough. Additionally, there were other repositories where the attackers should have deleted the comments after uploading the malicious code.