From f1144e1dd6377787f3c875318f09834127aa3d30 Mon Sep 17 00:00:00 2001 From: S3N4T0R <121706460+S3N4T0R-0X0@users.noreply.github.com> Date: Wed, 11 Sep 2024 15:19:00 -0400 Subject: [PATCH] Update README.md --- Chinese APT/Mustang Panda/README.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/Chinese APT/Mustang Panda/README.md b/Chinese APT/Mustang Panda/README.md index 4cee0b1..62ca8cc 100644 --- a/Chinese APT/Mustang Panda/README.md +++ b/Chinese APT/Mustang Panda/README.md @@ -70,6 +70,8 @@ Upon logging in, the attacker is directed to a Visual Studio Code web environmen Stately Taurus employed this method to deploy malware in compromised environments, carry out reconnaissance, and extract sensitive data. To ensure ongoing access to the reverse shell, the attacker set up persistence for a script called startcode.bat using a scheduled task that launches the shell. +If you need know more about ToneShell Backdoor: https://hunt.io/blog/toneshell-backdoor-used-to-target-attendees-of-the-iiss-defence-summit +![Screenshot from 2024-09-11 15-15-02](https://github.com/user-attachments/assets/c9b60539-4828-4eeb-9ea4-d319d746886b)