From de4f6a8e14511bb62dc680b5ab47c0866a446768 Mon Sep 17 00:00:00 2001 From: S3N4T0R <121706460+S3N4T0R-0X0@users.noreply.github.com> Date: Thu, 19 Sep 2024 15:36:51 -0400 Subject: [PATCH] Update README.md --- North Koreans APT/Labyrinth Chollima/README.md | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/North Koreans APT/Labyrinth Chollima/README.md b/North Koreans APT/Labyrinth Chollima/README.md index fb220a4..6e06e29 100644 --- a/North Koreans APT/Labyrinth Chollima/README.md +++ b/North Koreans APT/Labyrinth Chollima/README.md @@ -16,3 +16,14 @@ When accessed this way, the DLL files are loaded by the SumatraPDF.exe executabl 1.Create job description PDF file which will be sent spear phishing. + + + + +## The first stage (delivery technique) + +Since the attackers here wanted to target victims working on energy company and the aerospace industry, The attack starts with relies on legitimate job description content to target victims employed in U.S, Now I will create a pdf file with the same phishing message that the actual attackers used in their phishing campaign. + + +![Screenshot from 2024-09-19 15-34-00](https://github.com/user-attachments/assets/99564509-8016-49e9-aba7-925c89232f3d) +