Git Product home page Git Product logo

apt-attack-simulation's Introduction

APT-Attack-Simulation

A APT Attack Simulation for APT 29 & Lockbit

Authors

How does it works!

The attack contains main three stages

First Stage:

  • The attack begins with an email that contains a specially crafted HTML page that includes a malicious code. Upon opening the malicious page, an ISO file is downloaded that contains the malicious files.

  • The malicious file performs two actions

  1. Drops an ISO file (Second Stage)
  2. Sends a request to a malicious SMB server controlled by the attackers to steal the user's NTLM Hash for lateral spread.

Second Stage

  • The ISO file is opened and contains a forged lnk file that appears to be a PDF file from its icon, but it actually points to an exe file. When the exe file is executed, it opens the PDF file.

  • Upon execution of the malicious exe file, the PDF file is also executed. DLL and bin files are loaded, a registry key is added for persistence, and the DLL runs During this stage.

  • At this point, the attacker enables UAC bypass, gains system administrator privileges, hijack Windows Defender, and loads the malicious DLL instead of the original file. This allows the attacker to invisibly direct the malicious functions on the victim's machine, download more malware, and achieve system persistence.

Third Stage

Third stage

  • The DLL acts as a Loader to read the encrypted bin file and decrypt it in memory and try to hide from detection and run.

Disclaimer

Important Notice: This repository contains code and materials related to malware and other potentially harmful activities.

  • Limitation of Liability

The code and information provided in this repository are intended for educational and research purposes only. We explicitly disclaim any responsibility or liability for any illegal use, damage, or negative consequences resulting from the use of this code. By accessing or utilizing the code and materials in this repository, you acknowledge and accept that you are solely responsible for your actions and any associated outcomes.

  • Responsible Usage

We strongly discourage and condemn any form of illegal activities or malicious use of the code provided in this repository. It is essential to adhere to all applicable laws, regulations, and ethical guidelines when engaging with the information and code contained herein. We do not endorse, encourage, or support any unauthorized access, hacking, or malicious behavior.

  • Release of Liability

By using this repository, you agree to release the repository owner(s) from any liability, claims, or legal actions arising from your use, misuse, or interpretation of the code or information presented here. The repository owner(s) cannot be held accountable for any damages, losses, or adverse consequences incurred by individuals or organizations using this repository.

  • Ethical Considerations

We strongly urge users to prioritize ethical considerations and demonstrate responsible behavior when working with technology and code. Respecting the privacy, security, and rights of others is of utmost importance when utilizing any information or code found in this repository.

  • Compliance with Laws

Users are expected to fully comply with all local, national, and international laws and regulations relevant to their jurisdiction. Any misuse or unauthorized use of the code or information provided in this repository is strictly prohibited and may result in legal consequences.

  • Acknowledgment

We appreciate your understanding and cooperation in adhering to these terms. Please remember that technology and code should be used in a responsible, ethical, and positive manner.

apt-attack-simulation's People

Contributors

0xhossam avatar de3vil avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.