From d65263ff4cd6254b0708aaa254397a0cf5ebd3e9 Mon Sep 17 00:00:00 2001 From: S3N4T0R <121706460+S3N4T0R-0X0@users.noreply.github.com> Date: Fri, 14 Feb 2025 17:45:46 -0500 Subject: [PATCH] Update README.md --- North Koreans APT/Velvet Chollima/README.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/North Koreans APT/Velvet Chollima/README.md b/North Koreans APT/Velvet Chollima/README.md index ec25509..5cc9ac8 100644 --- a/North Koreans APT/Velvet Chollima/README.md +++ b/North Koreans APT/Velvet Chollima/README.md @@ -28,4 +28,6 @@ https://www.bleepingcomputer.com/news/security/fake-google-meet-conference-error ## The first stage (delivery technique) -First the attackers created PDF file includes a link that leads to a (Fake-Captcha) page. +First the attackers created PDF file includes a Hyperlink that leads to a (Fake-Captcha) page, The advantage of the hyperlink is that it does not appear in texts, and this is exactly what the attackers wanted to exploit. + +![Screenshot From 2025-02-14 17-40-19](https://github.com/user-attachments/assets/ffcebb81-af32-4700-83ed-1a916b6db8a5)