diff --git a/North Koreans APT/Velvet Chollima/README.md b/North Koreans APT/Velvet Chollima/README.md deleted file mode 100644 index a375e1c..0000000 --- a/North Koreans APT/Velvet Chollima/README.md +++ /dev/null @@ -1,5 +0,0 @@ -# Wicked Panda APT Adversary Simulation - -This is a simulation of attack by the Wicked Panda group (APT-41) targeting U.S. state government networks the attack campaign was active between May 2021 and February 2022, in addition to attacks targeting Taiwanese media, the attack chain starts with the in-memory execution of MoonWalk backdoor. Once the MoonWalk backdoor is successfully loaded by DodgeBox, the malware decrypts and reflectively loads two embedded plugins (C2 and Utility). The C2 plugin uses a custom encrypted C2 protocol to communicate with the attacker-controlled Google Drive account. -I relied on zscaler to figure out the details to make this simulation: https://www.zscaler.com/blogs/security-research/moonwalk-deep-dive-updated-arsenal-apt41-part-2 - diff --git a/North Koreans APT/Velvet Chollima/VELVET-CHOLLIMA_AU_500px.png b/North Koreans APT/Velvet Chollima/VELVET-CHOLLIMA_AU_500px.png deleted file mode 100644 index 6ea9fe1..0000000 Binary files a/North Koreans APT/Velvet Chollima/VELVET-CHOLLIMA_AU_500px.png and /dev/null differ