diff --git a/China/APT/APT27/2020-11-17/Analysis.md b/China/APT/APT27/2020-11-17/Analysis.md index 3f7e000..3ff9cff 100644 --- a/China/APT/APT27/2020-11-17/Analysis.md +++ b/China/APT/APT27/2020-11-17/Analysis.md @@ -1,4 +1,4 @@ -## APT27 rest active ? +## Rootkit 101 ### Initital approach

Thanks to KorbenD for sharing the sample recently detected by Thor (here).