From 80d56eb9744708ca45076b731eca8da2290661cd Mon Sep 17 00:00:00 2001 From: S3N4T0R <121706460+S3N4T0R-0X0@users.noreply.github.com> Date: Sun, 3 May 2026 06:00:50 -0400 Subject: [PATCH] Update README.md --- Iranian APT/Charming Kitten/README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Iranian APT/Charming Kitten/README.md b/Iranian APT/Charming Kitten/README.md index c03dbf2..e7d6801 100644 --- a/Iranian APT/Charming Kitten/README.md +++ b/Iranian APT/Charming Kitten/README.md @@ -15,7 +15,7 @@ and Group-IB: https://www.group-ib.com/blog/muddywater-operation-olalampo/ word-image-341009-175304-1-1262x700 -The attack group delivered a malicious Excel file designed to mimic the target’s internal financial records. The lure appeared as a legitimate spreadsheet containing payment details and cash flow projections. +The attack group delivered a malicious Excel and Word files designed to mimic the target’s internal financial records. The lure appeared as a legitimate spreadsheet containing payment details and cash flow projections. The infected document included specific references to “Engineering, Construction & Marine Services” and used local currency (AED), along with realistic transaction descriptions such as “Payroll Payments via WPS,” making it highly convincing to the target.