2025-08-25 19:00:42 -04:00
2025-04-25 12:00:27 -04:00
2025-08-25 19:00:42 -04:00
2025-07-06 04:23:33 -04:00
2025-08-14 07:58:40 -04:00

APT Attack Simulation

This repository is a compilation of all Russian, Chinese, Iranian and North Koreans APT simulations that target many vital sectors,both private and governmental. The simulation includes develop custom tools, C2 servers, backdoors, exploitation techniques, stagers, bootloaders, and many other tools that attackers might have used in actual attacks. These tools and TTPs are simulated here. I relied on PaloAlto Unit42, Kaspersky, Microsoft, Cisco, Trellix, CrowdStrike and WithSecure to figure out the details to make this simulations.

photo_2024-09-07_20-05-46

Caution

It's essential to note that this project is for educational and research purposes only, and any unauthorized use of it could lead to legal consequences.


The names of APT groups vary from one company to another, and in this simulations I have followed the names approved by CrowdStrike.

photo_2024-12-30_02-13-54

This all the names of the APTs was simulated one attack for each group

COUNTRY OF ORIGIN 🌐 Russia 🇷🇺 China 🇨🇳 North Korea 🇰🇵 Iran 🇮🇷
Cozy Bear Mustang Panda Labyrinth Chollima Helix Kitten
Voodoo Bear Glacial Panda Velvet Chollima Pioneer Kitten
Fancy Bear Wicked Panda Famous Chollima Clever Kitten
Energetic Bear Goblin Panda Stardust Chollima Static Kitten
Berserk Bear Anchor Panda Ricochet Chollima Tracer Kitten
Gossamer Bear Deep Panda Silent Chollima Nemesis Kitten
Primitive Bear Samurai Panda Spectral Kitten
Ember Bear Phantom Panda Charming Kitten
Venomous Bear Sunrise Panda
Ethereal Panda

All of this adversary simulation is powered by Bear-C2. https://github.com/S3N4T0R-0X0/BEAR

imageedit_6_6316175302

This is for research, awareness, and educational purposes, I am not responsible if anyone uses this technique for illegal purposes.

Languages
C++ 44.9%
Python 13.8%
PowerShell 9.9%
HTML 6.1%
Rust 5.8%
Other 19.5%