From c470a713b03f9a5e6e560bed4a3ea2b7356f3ced Mon Sep 17 00:00:00 2001 From: S3N4T0R <121706460+S3N4T0R-0X0@users.noreply.github.com> Date: Sun, 6 Jul 2025 12:22:08 -0400 Subject: [PATCH] Update README.md --- North Koreans APT/Famous Chollima/README.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/North Koreans APT/Famous Chollima/README.md b/North Koreans APT/Famous Chollima/README.md index 8b4e046..10a7389 100644 --- a/North Koreans APT/Famous Chollima/README.md +++ b/North Koreans APT/Famous Chollima/README.md @@ -122,6 +122,8 @@ It's important to ensure that the payload file has the same name as defined insi ![IMG_20250706_113049_180](https://github.com/user-attachments/assets/1f89cf15-055d-4e82-93aa-0e267874ca81) +The final result is the successful establishment of a Command and Control channel. This is achieved by delivering a phishing link that mimics Microsoft login pages using BEAR-C2’s phishing module combined with an obfuscated JavaScript payload. Once executed, the payload initiates a reverse TCP connection to the attacker’s server, encrypted with XOR, allowing secure data exfiltration and remote command execution. +