Update README.md

This commit is contained in:
S3N4T0R
2025-08-07 13:58:05 -04:00
committed by GitHub
parent 973efae5b6
commit 7d8747803a
@@ -110,6 +110,10 @@ Once connected:
Persistence (Runs at Startup): The script modifies the Windows Registry (Run key) to automatically start on reboot. Persistence (Runs at Startup): The script modifies the Windows Registry (Run key) to automatically start on reboot.
Every time the user logs in, the malicious script executes again, ensuring the attacker regains control. Every time the user logs in, the malicious script executes again, ensuring the attacker regains control.
## The fourth stage (payload connect to HTTPS-C2 Server)
C&C server on HTTPS: When a command is received, it is executed using the PowerShell command in Windows.
The output of the command is captured and sent back to the C2 server.