#kimsuky — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #kimsuky, aggregated by home.social.
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
Pulse ID: 6aa8f771c68a48adcc551965
Pulse Link: https://otx.alienvault.com/pulse/6aa8f771c68a48adcc551965
Pulse Author: Tr1sa111
Created: 2026-09-15 07:44:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
Pulse ID: 6aa8f771c68a48adcc551965
Pulse Link: https://otx.alienvault.com/pulse/6aa8f771c68a48adcc551965
Pulse Author: Tr1sa111
Created: 2026-09-15 07:44:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
Pulse ID: 6aa8f771c68a48adcc551965
Pulse Link: https://otx.alienvault.com/pulse/6aa8f771c68a48adcc551965
Pulse Author: Tr1sa111
Created: 2026-09-15 07:44:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
Pulse ID: 6aa8f771c68a48adcc551965
Pulse Link: https://otx.alienvault.com/pulse/6aa8f771c68a48adcc551965
Pulse Author: Tr1sa111
Created: 2026-09-15 07:44:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
Pulse ID: 6aa8f771c68a48adcc551965
Pulse Link: https://otx.alienvault.com/pulse/6aa8f771c68a48adcc551965
Pulse Author: Tr1sa111
Created: 2026-09-15 07:44:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Threat analysts reveal Kimsuky uses AI agent opencode to mass-produce phishing decoys. Discover how the group leverages AI to enhance its LNK attacks.
#Kimsuky #Opencode #AIAgent #CyberEspionage #Cybersecurity
https://securityonline.info/kimsuky-ai-agent-opencode/?utm_source=mastodon&utm_medium=jetpack_social
-
Threat analysts reveal Kimsuky uses AI agent opencode to mass-produce phishing decoys. Discover how the group leverages AI to enhance its LNK attacks.
#Kimsuky #Opencode #AIAgent #CyberEspionage #Cybersecurity
https://securityonline.info/kimsuky-ai-agent-opencode/?utm_source=mastodon&utm_medium=jetpack_social
-
Threat analysts reveal Kimsuky uses AI agent opencode to mass-produce phishing decoys. Discover how the group leverages AI to enhance its LNK attacks.
#Kimsuky #Opencode #AIAgent #CyberEspionage #Cybersecurity
https://securityonline.info/kimsuky-ai-agent-opencode/?utm_source=mastodon&utm_medium=jetpack_social
-
Threat analysts reveal Kimsuky uses AI agent opencode to mass-produce phishing decoys. Discover how the group leverages AI to enhance its LNK attacks.
#Kimsuky #Opencode #AIAgent #CyberEspionage #Cybersecurity
https://securityonline.info/kimsuky-ai-agent-opencode/?utm_source=mastodon&utm_medium=jetpack_social
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
Pulse ID: 6a9ff5d14ec39add3c2490d4
Pulse Link: https://otx.alienvault.com/pulse/6a9ff5d14ec39add3c2490d4
Pulse Author: Tr1sa111
Created: 2026-09-08 11:47:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #UK #bot #Tr1sa111
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
Pulse ID: 6a9ff5d14ec39add3c2490d4
Pulse Link: https://otx.alienvault.com/pulse/6a9ff5d14ec39add3c2490d4
Pulse Author: Tr1sa111
Created: 2026-09-08 11:47:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #UK #bot #Tr1sa111
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
Pulse ID: 6a9ff5d14ec39add3c2490d4
Pulse Link: https://otx.alienvault.com/pulse/6a9ff5d14ec39add3c2490d4
Pulse Author: Tr1sa111
Created: 2026-09-08 11:47:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #UK #bot #Tr1sa111
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
Pulse ID: 6a9ff5d14ec39add3c2490d4
Pulse Link: https://otx.alienvault.com/pulse/6a9ff5d14ec39add3c2490d4
Pulse Author: Tr1sa111
Created: 2026-09-08 11:47:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #UK #bot #Tr1sa111
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
Pulse ID: 6a9ff5d14ec39add3c2490d4
Pulse Link: https://otx.alienvault.com/pulse/6a9ff5d14ec39add3c2490d4
Pulse Author: Tr1sa111
Created: 2026-09-08 11:47:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #UK #bot #Tr1sa111
-
North Korea’s Kimsuky Hackers Turn to AI Coding Agents to Mass-Produce Phishing Lures
Genians researchers have linked a new Kimsuky campaign to the group's Operation GitPower cluster, revealing that the North Korean threat actor is now using an AI coding agent called OpenCode to generate phishing decoy documents at industrial scale. The campaign hides encrypted PowerShell loaders inside Windows shortcut files and leans on GitHub and Pastebin for command-and-control. -
North Korea’s Kimsuky Hackers Turn to AI Coding Agents to Mass-Produce Phishing Lures
Genians researchers have linked a new Kimsuky campaign to the group's Operation GitPower cluster, revealing that the North Korean threat actor is now using an AI coding agent called OpenCode to generate phishing decoy documents at industrial scale. The campaign hides encrypted PowerShell loaders inside Windows shortcut files and leans on GitHub and Pastebin for command-and-control. -
North Korea’s Kimsuky Hackers Turn to AI Coding Agents to Mass-Produce Phishing Lures
Genians researchers have linked a new Kimsuky campaign to the group's Operation GitPower cluster, revealing that the North Korean threat actor is now using an AI coding agent called OpenCode to generate phishing decoy documents at industrial scale. The campaign hides encrypted PowerShell loaders inside Windows shortcut files and leans on GitHub and Pastebin for command-and-control. -
North Korea’s Kimsuky Hackers Turn to AI Coding Agents to Mass-Produce Phishing Lures
Genians researchers have linked a new Kimsuky campaign to the group's Operation GitPower cluster, revealing that the North Korean threat actor is now using an AI coding agent called OpenCode to generate phishing decoy documents at industrial scale. The campaign hides encrypted PowerShell loaders inside Windows shortcut files and leans on GitHub and Pastebin for command-and-control. -
North Korea’s Kimsuky Hackers Turn to AI Coding Agents to Mass-Produce Phishing Lures
Genians researchers have linked a new Kimsuky campaign to the group's Operation GitPower cluster, revealing that the North Korean threat actor is now using an AI coding agent called OpenCode to generate phishing decoy documents at industrial scale. The campaign hides encrypted PowerShell loaders inside Windows shortcut files and leans on GitHub and Pastebin for command-and-control. -
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
The Kimsuky threat group continues Operation GitPower campaigns utilizing malicious LNK files disguised as financial and business documents. Thirteen LNK variants collected between August 11-19, 2026, employ GitHub Personal Access Tokens (PAT) for command-and-control communications, delivering obfuscated PowerShell loaders through custom decoders. Notable evolution includes anti-analysis routines detecting virtualization tools, Pastebin as alternative C2 infrastructure, and diversified decoy formats (PDF, XLSX, PNG). Metadata analysis reveals AI-generated content using the 'opencode' AI coding agent and HeadlessChrome PDF conversion, with placeholder text remaining unreviewed. The group maintains persistence through hidden scheduled tasks masquerading as legitimate software (BitLocker, MATLAB), while hardcoded GitHub PATs enable raw content retrieval. Despite increased sophistication in evasion techniques and decoy production automation, endpoint behaviors remain detectable through behavioral correlation a...
Pulse ID: 6a9e70fd7eb74853a795cc57
Pulse Link: https://otx.alienvault.com/pulse/6a9e70fd7eb74853a795cc57
Pulse Author: AlienVault
Created: 2026-09-07 08:08:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Chrome #CyberSecurity #Endpoint #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #PDF #PowerShell #RAT #UK #bot #AlienVault
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
The Kimsuky threat group continues Operation GitPower campaigns utilizing malicious LNK files disguised as financial and business documents. Thirteen LNK variants collected between August 11-19, 2026, employ GitHub Personal Access Tokens (PAT) for command-and-control communications, delivering obfuscated PowerShell loaders through custom decoders. Notable evolution includes anti-analysis routines detecting virtualization tools, Pastebin as alternative C2 infrastructure, and diversified decoy formats (PDF, XLSX, PNG). Metadata analysis reveals AI-generated content using the 'opencode' AI coding agent and HeadlessChrome PDF conversion, with placeholder text remaining unreviewed. The group maintains persistence through hidden scheduled tasks masquerading as legitimate software (BitLocker, MATLAB), while hardcoded GitHub PATs enable raw content retrieval. Despite increased sophistication in evasion techniques and decoy production automation, endpoint behaviors remain detectable through behavioral correlation a...
Pulse ID: 6a9e70fd7eb74853a795cc57
Pulse Link: https://otx.alienvault.com/pulse/6a9e70fd7eb74853a795cc57
Pulse Author: AlienVault
Created: 2026-09-07 08:08:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Chrome #CyberSecurity #Endpoint #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #PDF #PowerShell #RAT #UK #bot #AlienVault
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
The Kimsuky threat group continues Operation GitPower campaigns utilizing malicious LNK files disguised as financial and business documents. Thirteen LNK variants collected between August 11-19, 2026, employ GitHub Personal Access Tokens (PAT) for command-and-control communications, delivering obfuscated PowerShell loaders through custom decoders. Notable evolution includes anti-analysis routines detecting virtualization tools, Pastebin as alternative C2 infrastructure, and diversified decoy formats (PDF, XLSX, PNG). Metadata analysis reveals AI-generated content using the 'opencode' AI coding agent and HeadlessChrome PDF conversion, with placeholder text remaining unreviewed. The group maintains persistence through hidden scheduled tasks masquerading as legitimate software (BitLocker, MATLAB), while hardcoded GitHub PATs enable raw content retrieval. Despite increased sophistication in evasion techniques and decoy production automation, endpoint behaviors remain detectable through behavioral correlation a...
Pulse ID: 6a9e70fd7eb74853a795cc57
Pulse Link: https://otx.alienvault.com/pulse/6a9e70fd7eb74853a795cc57
Pulse Author: AlienVault
Created: 2026-09-07 08:08:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Chrome #CyberSecurity #Endpoint #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #PDF #PowerShell #RAT #UK #bot #AlienVault
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
The Kimsuky threat group continues Operation GitPower campaigns utilizing malicious LNK files disguised as financial and business documents. Thirteen LNK variants collected between August 11-19, 2026, employ GitHub Personal Access Tokens (PAT) for command-and-control communications, delivering obfuscated PowerShell loaders through custom decoders. Notable evolution includes anti-analysis routines detecting virtualization tools, Pastebin as alternative C2 infrastructure, and diversified decoy formats (PDF, XLSX, PNG). Metadata analysis reveals AI-generated content using the 'opencode' AI coding agent and HeadlessChrome PDF conversion, with placeholder text remaining unreviewed. The group maintains persistence through hidden scheduled tasks masquerading as legitimate software (BitLocker, MATLAB), while hardcoded GitHub PATs enable raw content retrieval. Despite increased sophistication in evasion techniques and decoy production automation, endpoint behaviors remain detectable through behavioral correlation a...
Pulse ID: 6a9e70fd7eb74853a795cc57
Pulse Link: https://otx.alienvault.com/pulse/6a9e70fd7eb74853a795cc57
Pulse Author: AlienVault
Created: 2026-09-07 08:08:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Chrome #CyberSecurity #Endpoint #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #PDF #PowerShell #RAT #UK #bot #AlienVault
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
The Kimsuky threat group continues Operation GitPower campaigns utilizing malicious LNK files disguised as financial and business documents. Thirteen LNK variants collected between August 11-19, 2026, employ GitHub Personal Access Tokens (PAT) for command-and-control communications, delivering obfuscated PowerShell loaders through custom decoders. Notable evolution includes anti-analysis routines detecting virtualization tools, Pastebin as alternative C2 infrastructure, and diversified decoy formats (PDF, XLSX, PNG). Metadata analysis reveals AI-generated content using the 'opencode' AI coding agent and HeadlessChrome PDF conversion, with placeholder text remaining unreviewed. The group maintains persistence through hidden scheduled tasks masquerading as legitimate software (BitLocker, MATLAB), while hardcoded GitHub PATs enable raw content retrieval. Despite increased sophistication in evasion techniques and decoy production automation, endpoint behaviors remain detectable through behavioral correlation a...
Pulse ID: 6a9e70fd7eb74853a795cc57
Pulse Link: https://otx.alienvault.com/pulse/6a9e70fd7eb74853a795cc57
Pulse Author: AlienVault
Created: 2026-09-07 08:08:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Chrome #CyberSecurity #Endpoint #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #PDF #PowerShell #RAT #UK #bot #AlienVault
-
Recent Kimsuky spear phishing campaigns abuse remote control tools and AI extensions to target victims in Japan and South Korea. Read the full analysis.
#Kimsuky #CyberSecurity #SpearPhishing #Malware #ThreatIntel
-
Recent Kimsuky spear phishing campaigns abuse remote control tools and AI extensions to target victims in Japan and South Korea. Read the full analysis.
#Kimsuky #CyberSecurity #SpearPhishing #Malware #ThreatIntel
-
Recent Kimsuky spear phishing campaigns abuse remote control tools and AI extensions to target victims in Japan and South Korea. Read the full analysis.
#Kimsuky #CyberSecurity #SpearPhishing #Malware #ThreatIntel
-
Recent Kimsuky spear phishing campaigns abuse remote control tools and AI extensions to target victims in Japan and South Korea. Read the full analysis.
#Kimsuky #CyberSecurity #SpearPhishing #Malware #ThreatIntel
-
ENKI WhiteHat found Kimsuky abusing legitimate tools like Chrome Remote Desktop and AnyDesk for stealthy persistence in phishing campaigns against South Korea and Japan.
#Kimsuky #ChromeRemoteDesktop #AnyDesk #Phishing #NorthKorea
-
North Korea Deploys AI-Built Chrome Extension to Steal Gmail
Kimsuky hackers used an AI-generated Chrome extension that automatically exfiltrates Gmail messages and attachments to North Korean servers
https://pulseofnations.lol/north-korea-deploys-ai/
#AI #ChromeExtension #Gmail #Kimsuky #NorthKorea #Phishing #StateSponsored
-
North Korea Deploys AI-Built Chrome Extension to Steal Gmail
Kimsuky hackers used an AI-generated Chrome extension that automatically exfiltrates Gmail messages and attachments to North Korean servers
https://pulseofnations.lol/north-korea-deploys-ai/
#AI #ChromeExtension #Gmail #Kimsuky #NorthKorea #Phishing #StateSponsored
-
North Korea Deploys AI-Built Chrome Extension to Steal Gmail
Kimsuky hackers used an AI-generated Chrome extension that automatically exfiltrates Gmail messages and attachments to North Korean servers
https://pulseofnations.lol/north-korea-deploys-ai/
#AI #ChromeExtension #Gmail #Kimsuky #NorthKorea #Phishing #StateSponsored
-
North Korea Deploys AI-Built Chrome Extension to Steal Gmail
Kimsuky hackers used an AI-generated Chrome extension that automatically exfiltrates Gmail messages and attachments to North Korean servers
https://pulseofnations.lol/north-korea-deploys-ai/
#AI #ChromeExtension #Gmail #Kimsuky #NorthKorea #Phishing #StateSponsored
-
📢 Kimsuky intègre des LLM locaux et des outils IA dans l'Opération GitPower
Cet article analyse l'Opération GitPower, une campagne d'espionnage cyber attribuée au groupe nord-coréen Kimsuky, détaillée initialement par le Genians Security Center.
📖 cyberveille : https://cyberveille.ch/posts/2026-08-18-kimsuky-integre-des-llm-locaux-et-des-outils-ia-dans-l-operation-gitpower/
🌐 source : https://blog.polyswarm.io/kimsuky-expands-ai-capabilities-through-a-local-ai-development-environment-in-operation-gitpower
🟢 vérification factuelle haute
#Kimsuky #APTNordCoréen #Cyberveille -
Kimsuky AI operations reveal a North Korea threat actor testing local LLMs. Suspected state hackers are building new capabilities to automate phishing.
#Kimsuky #CyberSecurity #LLM #NorthKorea #ThreatActor #Genians
https://securityonline.info/kimsuky-ai-operations/?utm_source=mastodon&utm_medium=jetpack_social
-
Kimsuky AI operations reveal a North Korea threat actor testing local LLMs. Suspected state hackers are building new capabilities to automate phishing.
#Kimsuky #CyberSecurity #LLM #NorthKorea #ThreatActor #Genians
https://securityonline.info/kimsuky-ai-operations/?utm_source=mastodon&utm_medium=jetpack_social
-
Kimsuky AI operations reveal a North Korea threat actor testing local LLMs. Suspected state hackers are building new capabilities to automate phishing.
#Kimsuky #CyberSecurity #LLM #NorthKorea #ThreatActor #Genians
https://securityonline.info/kimsuky-ai-operations/?utm_source=mastodon&utm_medium=jetpack_social
-
Kimsuky AI operations reveal a North Korea threat actor testing local LLMs. Suspected state hackers are building new capabilities to automate phishing.
#Kimsuky #CyberSecurity #LLM #NorthKorea #ThreatActor #Genians
https://securityonline.info/kimsuky-ai-operations/?utm_source=mastodon&utm_medium=jetpack_social
-
Kimsuky AI operations reveal a North Korea threat actor testing local LLMs. Suspected state hackers are building new capabilities to automate phishing.
#Kimsuky #CyberSecurity #LLM #NorthKorea #ThreatActor #Genians
https://securityonline.info/kimsuky-ai-operations/?utm_source=mastodon&utm_medium=jetpack_social
-
Like a villain's lair that also has a Michelin-star kitchen.
The craftsmanship is genuinely impressive. Every corridor of this operation is load-bearing danger. Operators: monitor outbound phishing campaigns and new malware samples for AI-enhanced hallmarks of Kimsuky's tradecraft.
Reward: You've received a Counterfeit Hallway — a passage that looks like progress but leads directly into a Kimsuky inbox lure.
#CyberSecurity #Kimsuky #Phishing #Malware #CyberEspionage #AI (2/2)
-
Like a villain's lair that also has a Michelin-star kitchen.
The craftsmanship is genuinely impressive. Every corridor of this operation is load-bearing danger. Operators: monitor outbound phishing campaigns and new malware samples for AI-enhanced hallmarks of Kimsuky's tradecraft.
Reward: You've received a Counterfeit Hallway — a passage that looks like progress but leads directly into a Kimsuky inbox lure.
#CyberSecurity #Kimsuky #Phishing #Malware #CyberEspionage #AI (2/2)
-
Like a villain's lair that also has a Michelin-star kitchen.
The craftsmanship is genuinely impressive. Every corridor of this operation is load-bearing danger. Operators: monitor outbound phishing campaigns and new malware samples for AI-enhanced hallmarks of Kimsuky's tradecraft.
Reward: You've received a Counterfeit Hallway — a passage that looks like progress but leads directly into a Kimsuky inbox lure.
#CyberSecurity #Kimsuky #Phishing #Malware #CyberEspionage #AI (2/2)
-
Genians has documented Kimsuky, a North Korean unit under the Reconnaissance General Bureau, building an offline AI stack on its own infrastructure. The group is not training custom models but assembling and testing existing AI tools to automate phishing, malware creation, and data exfiltration.
#Kimsuky #ThreatIntelligence #StateSponsored #AIsecurity
https://cyberworldops.eu/en/kimsuky-prepares-an-offline-ai-stack-to-enhance-phishing-malware-and
-
Genians has documented Kimsuky, a North Korean unit under the Reconnaissance General Bureau, building an offline AI stack on its own infrastructure. The group is not training custom models but assembling and testing existing AI tools to automate phishing, malware creation, and data exfiltration.
#Kimsuky #ThreatIntelligence #StateSponsored #AIsecurity
https://cyberworldops.eu/en/kimsuky-prepares-an-offline-ai-stack-to-enhance-phishing-malware-and
-
北韓黑客「Kimsuky」疑強化AI功能 加速網攻自動化
https://www.am730.com.hk/科技/1046651/北韓黑客-kimsuky-疑強化ai功能-加速網攻自動化 -
北韓黑客「Kimsuky」疑強化AI功能 加速網攻自動化
https://www.am730.com.hk/科技/1046651/北韓黑客-kimsuky-疑強化ai功能-加速網攻自動化 -
北韓黑客「Kimsuky」疑強化AI功能 加速網攻自動化
https://www.am730.com.hk/科技/1046651/北韓黑客-kimsuky-疑強化ai功能-加速網攻自動化 -
📢 Kimsuky / Operation GitPower : LLM locaux, AsyncRAT chiffré et C2 GitHub
Ce rapport de threat intelligence documente Operation GitPower, une campagne attribuée au groupe nord-coréen Kimsuky (opérant sous le Reconnaissance General Bureau). Il s'inscrit dans la continuité de la campagne FlowerPower (2023) et d'une campagne de 2024 déguisée en éditorial…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-10-kimsuky-operation-gitpower-llm-locaux-asyncrat-chiffre-et-c2-github/
🌐 source : https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm
🟡 vérification factuelle moyenne
#AsyncRAT #Kimsuky #Cyberveille -
North Korean Spy Group Kimsuky Built Offline AI Lab on Attack Servers to Analyze Stolen Files
Students and members of the public read in a library at the Grand People’s Study House near Kim…
#EuropeSays #Korea #KR #AIPhishing #GeniansSecurityCenter #Kimsuky #Korean #localllm #NorthKoreahacking #NorthKoreanhackers #OperationGitPower #phishingdetection
https://www.europesays.com/korea/114620/ -
North Korean Hacker Group ‘Kimsuky’ Suspected of Independently Developing AI Tools for Cyberattacks — BigGo Finance
It has come to light that the hacker group “Kimsuky,” believed to have deep ties to the North…
#EuropeSays #Korea #KR #Cursor #Genians #GPT4All #Kimsuky #Korean #LargeLanguageModel(LLM) #Msty #NorthKorea #Ollama #Retrieval-AugmentedGeneration(RAG) #U.S.TreasuryDepartment
https://www.europesays.com/korea/114139/ -
ENKI WhiteHat and AhnLab documented the operation. Kimsuky remains sanctioned by the U.S. government since 2023. The threat actor has not filed an appeal. The threat actor will not file an appeal.
Audit your groupware vendors and their SaaS environments for unauthorized access and scan for Gomir infections immediately.
Reward: You've received a Deprecated Trust Anchor. It does nothing.
#APT43 #Kimsuky #SouthKorea #CyberSecurity #Malware #CompromisedAndCounted (2/2)
-
ENKI WhiteHat and AhnLab documented the operation. Kimsuky remains sanctioned by the U.S. government since 2023. The threat actor has not filed an appeal. The threat actor will not file an appeal.
Audit your groupware vendors and their SaaS environments for unauthorized access and scan for Gomir infections immediately.
Reward: You've received a Deprecated Trust Anchor. It does nothing.
#APT43 #Kimsuky #SouthKorea #CyberSecurity #Malware #CompromisedAndCounted (2/2)
-
Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant
#Kimsuky #HttpSpy
https://www.enki.co.kr/en/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant -
Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant
#Kimsuky #HttpSpy
https://www.enki.co.kr/en/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant -
Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant
#Kimsuky #HttpSpy
https://www.enki.co.kr/en/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant -
Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant
#Kimsuky #HttpSpy
https://www.enki.co.kr/en/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant -
Kimsuky Expands Malware Arsenal with HTTPSpy, HelloDoor
Kimsuky, a notorious North Korean hacking group, has upgraded its malware arsenal with HTTPSpy and HelloDoor, using clever tactics like fake installation pages and a spoofed Webex meeting to infiltrate targets. The group's latest attacks involve highly tailored social engineering and real-time infection verification to maximize success.
#Kimsuky #NorthKorea #Statesponsored #MalwareOperations #SocialEngineering
-
Kimsuky-linked campaigns are deploying PebbleDash and AppleSeed malware against government and defense targets.
Researchers say the operators abused VSCode tunneling, GitHub authentication, DWAgent, and Cloudflare Quick Tunnels post-compromise.
https://www.technadu.com/kimsuky-pebbledash-and-appleseed-malware-campaigns/627884/
-
Kimsuky-linked campaigns are deploying PebbleDash and AppleSeed malware against government and defense targets.
Researchers say the operators abused VSCode tunneling, GitHub authentication, DWAgent, and Cloudflare Quick Tunnels post-compromise.
https://www.technadu.com/kimsuky-pebbledash-and-appleseed-malware-campaigns/627884/
-
Kimsuky APT Expands Arsenal with Advanced PebbleDash Malware Tools
Kimsuky's malware arsenal just got a major boost with the addition of advanced PebbleDash tools, allowing the group to infiltrate systems with even more sophisticated tactics. Their latest campaign uses clever spear-phishing and malicious attachments to catch victims off guard.