From ad94a08fdc4e2158d4b485dab31960b67d180907 Mon Sep 17 00:00:00 2001 From: S3N4T0R <121706460+S3N4T0R-0X0@users.noreply.github.com> Date: Thu, 9 Oct 2025 12:01:12 -0400 Subject: [PATCH] Update README.md --- North Koreans APT/Ricochet Chollima/README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/North Koreans APT/Ricochet Chollima/README.md b/North Koreans APT/Ricochet Chollima/README.md index 6689ded..efb8797 100644 --- a/North Koreans APT/Ricochet Chollima/README.md +++ b/North Koreans APT/Ricochet Chollima/README.md @@ -69,6 +69,7 @@ https://github.com/user-attachments/assets/45420912-5110-49eb-b64a-531410459f94 When the PowerShell command in “toy03.bat” executes, it loads the “toy02.dat” file created in the temporary folder to function as a loader; the embedded PowerShell within “toy02.dat” then runs and loads “toy01.dat” from the same folder, during which XOR transformed data is decoded and mapped into memory and a new thread is spawned; as a result, the shellcode is placed in memory and the region is made executable, after which another thread is created to run the memory-resident code constituting a fileless technique for dynamic code execution and runtime malware injection. +Screenshot From 2025-10-09 12-00-21