From c907eab0d68ae458bdd80d97ada97c4e1c1e6588 Mon Sep 17 00:00:00 2001 From: S3N4T0R <121706460+S3N4T0R-0X0@users.noreply.github.com> Date: Fri, 20 Sep 2024 18:08:06 -0400 Subject: [PATCH] Update README.md --- North Koreans APT/Labyrinth Chollima/README.md | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/North Koreans APT/Labyrinth Chollima/README.md b/North Koreans APT/Labyrinth Chollima/README.md index 314c204..fd95cc7 100644 --- a/North Koreans APT/Labyrinth Chollima/README.md +++ b/North Koreans APT/Labyrinth Chollima/README.md @@ -40,8 +40,7 @@ After that I will use Shellter to inject DLL in the Sumatra pdf.exe which I will ![Screenshot from 2024-09-20 17-34-18](https://github.com/user-attachments/assets/8bcfa575-2d4f-4ba7-939e-b96d6156a75b) - - +After injecting the malicious DLL into (SumatraPDF.exe), I will bundle it with a non-malicious (job description.pdf) file inside a ZIP archive. When the user clicks on the PDF file, it will trigger the background execution of the injected (SumatraPDF.exe), which will establish a reverse connection.