#kimsuky — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #kimsuky, aggregated by home.social.
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
Pulse ID: 6a9ff5d14ec39add3c2490d4
Pulse Link: https://otx.alienvault.com/pulse/6a9ff5d14ec39add3c2490d4
Pulse Author: Tr1sa111
Created: 2026-09-08 11:47:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #UK #bot #Tr1sa111
-
North Korea’s Kimsuky Hackers Turn to AI Coding Agents to Mass-Produce Phishing Lures
Genians researchers have linked a new Kimsuky campaign to the group's Operation GitPower cluster, revealing that the North Korean threat actor is now using an AI coding agent called OpenCode to generate phishing decoy documents at industrial scale. The campaign hides encrypted PowerShell loaders inside Windows shortcut files and leans on GitHub and Pastebin for command-and-control. -
North Korea’s Kimsuky Hackers Turn to AI Coding Agents to Mass-Produce Phishing Lures
Genians researchers have linked a new Kimsuky campaign to the group's Operation GitPower cluster, revealing that the North Korean threat actor is now using an AI coding agent called OpenCode to generate phishing decoy documents at industrial scale. The campaign hides encrypted PowerShell loaders inside Windows shortcut files and leans on GitHub and Pastebin for command-and-control. -
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
The Kimsuky threat group continues Operation GitPower campaigns utilizing malicious LNK files disguised as financial and business documents. Thirteen LNK variants collected between August 11-19, 2026, employ GitHub Personal Access Tokens (PAT) for command-and-control communications, delivering obfuscated PowerShell loaders through custom decoders. Notable evolution includes anti-analysis routines detecting virtualization tools, Pastebin as alternative C2 infrastructure, and diversified decoy formats (PDF, XLSX, PNG). Metadata analysis reveals AI-generated content using the 'opencode' AI coding agent and HeadlessChrome PDF conversion, with placeholder text remaining unreviewed. The group maintains persistence through hidden scheduled tasks masquerading as legitimate software (BitLocker, MATLAB), while hardcoded GitHub PATs enable raw content retrieval. Despite increased sophistication in evasion techniques and decoy production automation, endpoint behaviors remain detectable through behavioral correlation a...
Pulse ID: 6a9e70fd7eb74853a795cc57
Pulse Link: https://otx.alienvault.com/pulse/6a9e70fd7eb74853a795cc57
Pulse Author: AlienVault
Created: 2026-09-07 08:08:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Chrome #CyberSecurity #Endpoint #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #PDF #PowerShell #RAT #UK #bot #AlienVault
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
The Kimsuky threat group continues Operation GitPower campaigns utilizing malicious LNK files disguised as financial and business documents. Thirteen LNK variants collected between August 11-19, 2026, employ GitHub Personal Access Tokens (PAT) for command-and-control communications, delivering obfuscated PowerShell loaders through custom decoders. Notable evolution includes anti-analysis routines detecting virtualization tools, Pastebin as alternative C2 infrastructure, and diversified decoy formats (PDF, XLSX, PNG). Metadata analysis reveals AI-generated content using the 'opencode' AI coding agent and HeadlessChrome PDF conversion, with placeholder text remaining unreviewed. The group maintains persistence through hidden scheduled tasks masquerading as legitimate software (BitLocker, MATLAB), while hardcoded GitHub PATs enable raw content retrieval. Despite increased sophistication in evasion techniques and decoy production automation, endpoint behaviors remain detectable through behavioral correlation a...
Pulse ID: 6a9e70fd7eb74853a795cc57
Pulse Link: https://otx.alienvault.com/pulse/6a9e70fd7eb74853a795cc57
Pulse Author: AlienVault
Created: 2026-09-07 08:08:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Chrome #CyberSecurity #Endpoint #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #PDF #PowerShell #RAT #UK #bot #AlienVault
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
The Kimsuky threat group continues Operation GitPower campaigns utilizing malicious LNK files disguised as financial and business documents. Thirteen LNK variants collected between August 11-19, 2026, employ GitHub Personal Access Tokens (PAT) for command-and-control communications, delivering obfuscated PowerShell loaders through custom decoders. Notable evolution includes anti-analysis routines detecting virtualization tools, Pastebin as alternative C2 infrastructure, and diversified decoy formats (PDF, XLSX, PNG). Metadata analysis reveals AI-generated content using the 'opencode' AI coding agent and HeadlessChrome PDF conversion, with placeholder text remaining unreviewed. The group maintains persistence through hidden scheduled tasks masquerading as legitimate software (BitLocker, MATLAB), while hardcoded GitHub PATs enable raw content retrieval. Despite increased sophistication in evasion techniques and decoy production automation, endpoint behaviors remain detectable through behavioral correlation a...
Pulse ID: 6a9e70fd7eb74853a795cc57
Pulse Link: https://otx.alienvault.com/pulse/6a9e70fd7eb74853a795cc57
Pulse Author: AlienVault
Created: 2026-09-07 08:08:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Chrome #CyberSecurity #Endpoint #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #PDF #PowerShell #RAT #UK #bot #AlienVault
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
The Kimsuky threat group continues Operation GitPower campaigns utilizing malicious LNK files disguised as financial and business documents. Thirteen LNK variants collected between August 11-19, 2026, employ GitHub Personal Access Tokens (PAT) for command-and-control communications, delivering obfuscated PowerShell loaders through custom decoders. Notable evolution includes anti-analysis routines detecting virtualization tools, Pastebin as alternative C2 infrastructure, and diversified decoy formats (PDF, XLSX, PNG). Metadata analysis reveals AI-generated content using the 'opencode' AI coding agent and HeadlessChrome PDF conversion, with placeholder text remaining unreviewed. The group maintains persistence through hidden scheduled tasks masquerading as legitimate software (BitLocker, MATLAB), while hardcoded GitHub PATs enable raw content retrieval. Despite increased sophistication in evasion techniques and decoy production automation, endpoint behaviors remain detectable through behavioral correlation a...
Pulse ID: 6a9e70fd7eb74853a795cc57
Pulse Link: https://otx.alienvault.com/pulse/6a9e70fd7eb74853a795cc57
Pulse Author: AlienVault
Created: 2026-09-07 08:08:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Chrome #CyberSecurity #Endpoint #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #PDF #PowerShell #RAT #UK #bot #AlienVault
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
The Kimsuky threat group continues Operation GitPower campaigns utilizing malicious LNK files disguised as financial and business documents. Thirteen LNK variants collected between August 11-19, 2026, employ GitHub Personal Access Tokens (PAT) for command-and-control communications, delivering obfuscated PowerShell loaders through custom decoders. Notable evolution includes anti-analysis routines detecting virtualization tools, Pastebin as alternative C2 infrastructure, and diversified decoy formats (PDF, XLSX, PNG). Metadata analysis reveals AI-generated content using the 'opencode' AI coding agent and HeadlessChrome PDF conversion, with placeholder text remaining unreviewed. The group maintains persistence through hidden scheduled tasks masquerading as legitimate software (BitLocker, MATLAB), while hardcoded GitHub PATs enable raw content retrieval. Despite increased sophistication in evasion techniques and decoy production automation, endpoint behaviors remain detectable through behavioral correlation a...
Pulse ID: 6a9e70fd7eb74853a795cc57
Pulse Link: https://otx.alienvault.com/pulse/6a9e70fd7eb74853a795cc57
Pulse Author: AlienVault
Created: 2026-09-07 08:08:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Chrome #CyberSecurity #Endpoint #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #PDF #PowerShell #RAT #UK #bot #AlienVault