mirror of
https://github.com/S3N4T0R-0X0/APTs-Adversary-Simulation.git
synced 2026-08-04 09:41:40 +02:00
Update README.md
This commit is contained in:
@@ -121,7 +121,7 @@ The value points to `C:\\Windows\\System32\\payload.dll` (a likely misconfigurat
|
||||
|
||||
Uses Windows' Winsock API to set up the socket connection to the attacker.
|
||||
|
||||
## The fourth stage (Data Exfiltration) over OneDrive API C2 Channe
|
||||
## The fourth stage (Data Exfiltration) over Google Drive API C2 Channe
|
||||
|
||||
I have previously performed Data Exfiltration during an APT28 attack via OneDrive. You can refer to this link: https://github.com/S3N4T0R-0X0/APT-Attack-Simulation/tree/main/Russian%20APT/APT28-Adversary-Simulation for detailed steps on how this can be accomplished. However, in this particular attack, a more advanced and non-open-source version of BEAR-C2 was utilized for Data Exfiltration.
|
||||
|
||||
@@ -131,12 +131,12 @@ We will use the Application (client) ID for the inputs needed by the C2 server
|
||||
|
||||

|
||||
|
||||
After that, we will go to the Certificates & secrets menu to generate the Secret ID for the Microsoft Azure account, and this is what we will use in OneDrive C2.
|
||||
After that, we will go to the Certificates & secrets menu to generate the Secret ID for the Microsoft Azure account, and this is what we will use in Google Drive C2.
|
||||
|
||||

|
||||
|
||||
|
||||
## Final result: payload connect to OneDrive By using BEAR-C2
|
||||
## Final result: payload connect to Google Drive By using BEAR-C2
|
||||
|
||||

|
||||
|
||||
|
||||
Reference in New Issue
Block a user