From f8e8e4a4d8d962a73f3a7ae2bc31251eaa0fcff5 Mon Sep 17 00:00:00 2001 From: S3N4T0R <121706460+S3N4T0R-0X0@users.noreply.github.com> Date: Sun, 24 Aug 2025 17:25:21 -0400 Subject: [PATCH] Update README.md --- North Koreans APT/Ricochet Chollima/README.md | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/North Koreans APT/Ricochet Chollima/README.md b/North Koreans APT/Ricochet Chollima/README.md index f809f5e..af6ccf2 100644 --- a/North Koreans APT/Ricochet Chollima/README.md +++ b/North Koreans APT/Ricochet Chollima/README.md @@ -1,6 +1,10 @@ # Ricochet Chollima APT Adversary Simulation -This is a simulation of an attack by the (Ricochet Chollima) APT group, targeting several activists focused on North Korea. The attack campaign began in March 2025. The attack chain started with spear-phishing. The email contained a Dropbox link leading to a compressed archive that included a malicious shortcut (LNK) file. When extracted and executed, the LNK file activated additional malware containing the keyword "toy." The content was disguised as an academic forum invitation from a South Korean national security think tank to attract attention. This simulation is based on research from Genians: https://www.genians.co.kr/en/blog/threat_intelligence/toybox-story +This is a simulation of an attack by the (Ricochet Chollima) APT group, targeting several activists focused on North Korea. The attack campaign began in March 2025. The attack chain started with spear-phishing. The email contained a Dropbox link leading to a compressed archive that included a malicious shortcut (LNK) file. When extracted and executed, the LNK file activated additional malware containing the keyword "toy." The content was disguised as an academic forum invitation from a South Korean national security think tank to attract attention. + +This simulation is based on research from Genians: https://www.genians.co.kr/en/blog/threat_intelligence/toybox-story + +