835 B
Velvet Chollima APT Adversary Simulation
This is a simulation of attack by the Velvet Chollima APT group targeting South Korean government official the attack campaign was starting January 2025, in addition to attacks targeting NGOs, government agencies, and media companies across North America, South America, Europe, and East Asia, the attack chain starts with the spear-phishing email with a PDF attachment. However, targets that want to read the document are directed to a fake device registration link that instructs them to run PowerShell as an administrator and paste attacker-provided code. I relied on Microsoft's Threat Intelligence and bleeping computer to figure out the details to make this simulation: https://www.bleepingcomputer.com/news/security/dprk-hackers-dupe-targets-into-typing-powershell-commands-as-admin/