Files
APTs-Adversary-Simulation/North Koreans APT/Silent Chollima
2025-12-23 04:02:49 -05:00
..
2025-12-22 04:42:10 -05:00
2025-12-23 04:02:49 -05:00

Silent Chollima APT Adversary Simulation

This is a simulation of attack by (Silent Chollima) APT group targeting several customers and their users in North America, Asia, and Europe. The attack campaign was active in June 2025, have sent a link leading to a ZIP or RAR archive file. Inside this file would be a legitimate executable that was given a filename relevant to the targeted organization or tied to the theme of the spear phish email.When executed, this legitimate executable would load a malicious payload in an included Dynamic Link Library (DLL), via search order hijacking which provided operators with the ability to remotely execute commands on infected devices. I relied on volexity to figure out the details to make this: https://www.volexity.com/blog/2025/10/08/apt-meets-gpt-targeted-operations-with-untamed-llms/

1623606708028