diff --git a/North Koreans APT/Labyrinth Chollima/README.md b/North Koreans APT/Labyrinth Chollima/README.md index 3ef9c27..fec1f58 100644 --- a/North Koreans APT/Labyrinth Chollima/README.md +++ b/North Koreans APT/Labyrinth Chollima/README.md @@ -13,14 +13,14 @@ When accessed this way, the DLL files are loaded by the SumatraPDF.exe executabl ![imageedit_5_5991500850](https://github.com/user-attachments/assets/2c6f83ad-eab6-4445-98ec-5265d1b6dd34) -1.Create job description PDF file which will be sent spear phishing. +1. Create job description PDF file which will be sent spear phishing. -2.Use Shellter to inject DLL in the Sumatra pdf.exe which I will use in the attack through the pdf file that is used in the phishing campaign. +2. Use Shellter to inject DLL in the Sumatra pdf.exe which I will use in the attack through the pdf file that is used in the phishing campaign. -3.Executes the PDF file while simultaneously running (SumatraPDF.exe) in the background. This executable contains the DLL payload, through which I will establish the reverse connection. +3. Executes the PDF file while simultaneously running (SumatraPDF.exe) in the background. This executable contains the DLL payload, through which I will establish the reverse connection. -4.Waits for the incoming connection from the backdoor to data exfiltration when it is executed on the target machine. +4. Waits for the incoming connection from the backdoor to data exfiltration when it is executed on the target machine.