home.social

#kimsuky — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #kimsuky, aggregated by home.social.

  1. Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve

    Pulse ID: 6a9ff5d14ec39add3c2490d4
    Pulse Link: otx.alienvault.com/pulse/6a9ff
    Pulse Author: Tr1sa111
    Created: 2026-09-08 11:47:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #UK #bot #Tr1sa111

  2. Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve

    Pulse ID: 6a9ff5d14ec39add3c2490d4
    Pulse Link: otx.alienvault.com/pulse/6a9ff
    Pulse Author: Tr1sa111
    Created: 2026-09-08 11:47:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #UK #bot #Tr1sa111

  3. Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve

    Pulse ID: 6a9ff5d14ec39add3c2490d4
    Pulse Link: otx.alienvault.com/pulse/6a9ff
    Pulse Author: Tr1sa111
    Created: 2026-09-08 11:47:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #UK #bot #Tr1sa111

  4. Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve

    Pulse ID: 6a9ff5d14ec39add3c2490d4
    Pulse Link: otx.alienvault.com/pulse/6a9ff
    Pulse Author: Tr1sa111
    Created: 2026-09-08 11:47:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #UK #bot #Tr1sa111

  5. Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve

    Pulse ID: 6a9ff5d14ec39add3c2490d4
    Pulse Link: otx.alienvault.com/pulse/6a9ff
    Pulse Author: Tr1sa111
    Created: 2026-09-08 11:47:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #UK #bot #Tr1sa111

  6. North Korea’s Kimsuky Hackers Turn to AI Coding Agents to Mass-Produce Phishing Lures

    Genians researchers have linked a new Kimsuky campaign to the group's Operation GitPower cluster, revealing that the North Korean threat actor is now using an AI coding agent called OpenCode to generate phishing decoy documents at industrial scale. The campaign hides encrypted PowerShell loaders inside Windows shortcut files and leans on GitHub and Pastebin for command-and-control.

    securebulletin.com/north-korea

  7. North Korea’s Kimsuky Hackers Turn to AI Coding Agents to Mass-Produce Phishing Lures

    Genians researchers have linked a new Kimsuky campaign to the group's Operation GitPower cluster, revealing that the North Korean threat actor is now using an AI coding agent called OpenCode to generate phishing decoy documents at industrial scale. The campaign hides encrypted PowerShell loaders inside Windows shortcut files and leans on GitHub and Pastebin for command-and-control.

    securebulletin.com/north-korea

  8. North Korea’s Kimsuky Hackers Turn to AI Coding Agents to Mass-Produce Phishing Lures

    Genians researchers have linked a new Kimsuky campaign to the group's Operation GitPower cluster, revealing that the North Korean threat actor is now using an AI coding agent called OpenCode to generate phishing decoy documents at industrial scale. The campaign hides encrypted PowerShell loaders inside Windows shortcut files and leans on GitHub and Pastebin for command-and-control.

    securebulletin.com/north-korea

  9. North Korea’s Kimsuky Hackers Turn to AI Coding Agents to Mass-Produce Phishing Lures

    Genians researchers have linked a new Kimsuky campaign to the group's Operation GitPower cluster, revealing that the North Korean threat actor is now using an AI coding agent called OpenCode to generate phishing decoy documents at industrial scale. The campaign hides encrypted PowerShell loaders inside Windows shortcut files and leans on GitHub and Pastebin for command-and-control.

    securebulletin.com/north-korea

  10. North Korea’s Kimsuky Hackers Turn to AI Coding Agents to Mass-Produce Phishing Lures

    Genians researchers have linked a new Kimsuky campaign to the group's Operation GitPower cluster, revealing that the North Korean threat actor is now using an AI coding agent called OpenCode to generate phishing decoy documents at industrial scale. The campaign hides encrypted PowerShell loaders inside Windows shortcut files and leans on GitHub and Pastebin for command-and-control.

    securebulletin.com/north-korea

  11. Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

    Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.

    Pulse ID: 6a873495a873c0ec3c6d9880
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:08:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault