From d22e7c0d44fbc3984e0cf8196caaa82341b406e0 Mon Sep 17 00:00:00 2001 From: S3N4T0R <121706460+S3N4T0R-0X0@users.noreply.github.com> Date: Sun, 24 Aug 2025 18:33:44 -0400 Subject: [PATCH] Update README.md --- North Koreans APT/Ricochet Chollima/README.md | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/North Koreans APT/Ricochet Chollima/README.md b/North Koreans APT/Ricochet Chollima/README.md index a5187c1..ccc94c4 100644 --- a/North Koreans APT/Ricochet Chollima/README.md +++ b/North Koreans APT/Ricochet Chollima/README.md @@ -17,3 +17,9 @@ The attacker impersonated a North Korea-focused expert based in South Korea, and 2. malicious shortcut: make single shortcut (LNK) file. This LNK file executes malicious code and shares the same name as the ZIP archive, with only the file extension being different. +3. PowerShell commands: The shortcut (LNK) file is configured to run via PowerShell commands embedded arguments. + +4. toy.bat: When the PowerShell command in “toy03.bat” file is executed, it loads “toy02.dat” file created in temporary folder, functioning as a loader. + +5. +