#kimsuky — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #kimsuky, aggregated by home.social.
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
Pulse ID: 6a9ff5d14ec39add3c2490d4
Pulse Link: https://otx.alienvault.com/pulse/6a9ff5d14ec39add3c2490d4
Pulse Author: Tr1sa111
Created: 2026-09-08 11:47:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #UK #bot #Tr1sa111
-
North Korea’s Kimsuky Hackers Turn to AI Coding Agents to Mass-Produce Phishing Lures
Genians researchers have linked a new Kimsuky campaign to the group's Operation GitPower cluster, revealing that the North Korean threat actor is now using an AI coding agent called OpenCode to generate phishing decoy documents at industrial scale. The campaign hides encrypted PowerShell loaders inside Windows shortcut files and leans on GitHub and Pastebin for command-and-control. -
North Korea’s Kimsuky Hackers Turn to AI Coding Agents to Mass-Produce Phishing Lures
Genians researchers have linked a new Kimsuky campaign to the group's Operation GitPower cluster, revealing that the North Korean threat actor is now using an AI coding agent called OpenCode to generate phishing decoy documents at industrial scale. The campaign hides encrypted PowerShell loaders inside Windows shortcut files and leans on GitHub and Pastebin for command-and-control. -
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
The Kimsuky threat group continues Operation GitPower campaigns utilizing malicious LNK files disguised as financial and business documents. Thirteen LNK variants collected between August 11-19, 2026, employ GitHub Personal Access Tokens (PAT) for command-and-control communications, delivering obfuscated PowerShell loaders through custom decoders. Notable evolution includes anti-analysis routines detecting virtualization tools, Pastebin as alternative C2 infrastructure, and diversified decoy formats (PDF, XLSX, PNG). Metadata analysis reveals AI-generated content using the 'opencode' AI coding agent and HeadlessChrome PDF conversion, with placeholder text remaining unreviewed. The group maintains persistence through hidden scheduled tasks masquerading as legitimate software (BitLocker, MATLAB), while hardcoded GitHub PATs enable raw content retrieval. Despite increased sophistication in evasion techniques and decoy production automation, endpoint behaviors remain detectable through behavioral correlation a...
Pulse ID: 6a9e70fd7eb74853a795cc57
Pulse Link: https://otx.alienvault.com/pulse/6a9e70fd7eb74853a795cc57
Pulse Author: AlienVault
Created: 2026-09-07 08:08:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Chrome #CyberSecurity #Endpoint #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #PDF #PowerShell #RAT #UK #bot #AlienVault
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
The Kimsuky threat group continues Operation GitPower campaigns utilizing malicious LNK files disguised as financial and business documents. Thirteen LNK variants collected between August 11-19, 2026, employ GitHub Personal Access Tokens (PAT) for command-and-control communications, delivering obfuscated PowerShell loaders through custom decoders. Notable evolution includes anti-analysis routines detecting virtualization tools, Pastebin as alternative C2 infrastructure, and diversified decoy formats (PDF, XLSX, PNG). Metadata analysis reveals AI-generated content using the 'opencode' AI coding agent and HeadlessChrome PDF conversion, with placeholder text remaining unreviewed. The group maintains persistence through hidden scheduled tasks masquerading as legitimate software (BitLocker, MATLAB), while hardcoded GitHub PATs enable raw content retrieval. Despite increased sophistication in evasion techniques and decoy production automation, endpoint behaviors remain detectable through behavioral correlation a...
Pulse ID: 6a9e70fd7eb74853a795cc57
Pulse Link: https://otx.alienvault.com/pulse/6a9e70fd7eb74853a795cc57
Pulse Author: AlienVault
Created: 2026-09-07 08:08:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Chrome #CyberSecurity #Endpoint #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #PDF #PowerShell #RAT #UK #bot #AlienVault
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
The Kimsuky threat group continues Operation GitPower campaigns utilizing malicious LNK files disguised as financial and business documents. Thirteen LNK variants collected between August 11-19, 2026, employ GitHub Personal Access Tokens (PAT) for command-and-control communications, delivering obfuscated PowerShell loaders through custom decoders. Notable evolution includes anti-analysis routines detecting virtualization tools, Pastebin as alternative C2 infrastructure, and diversified decoy formats (PDF, XLSX, PNG). Metadata analysis reveals AI-generated content using the 'opencode' AI coding agent and HeadlessChrome PDF conversion, with placeholder text remaining unreviewed. The group maintains persistence through hidden scheduled tasks masquerading as legitimate software (BitLocker, MATLAB), while hardcoded GitHub PATs enable raw content retrieval. Despite increased sophistication in evasion techniques and decoy production automation, endpoint behaviors remain detectable through behavioral correlation a...
Pulse ID: 6a9e70fd7eb74853a795cc57
Pulse Link: https://otx.alienvault.com/pulse/6a9e70fd7eb74853a795cc57
Pulse Author: AlienVault
Created: 2026-09-07 08:08:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Chrome #CyberSecurity #Endpoint #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #PDF #PowerShell #RAT #UK #bot #AlienVault
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
The Kimsuky threat group continues Operation GitPower campaigns utilizing malicious LNK files disguised as financial and business documents. Thirteen LNK variants collected between August 11-19, 2026, employ GitHub Personal Access Tokens (PAT) for command-and-control communications, delivering obfuscated PowerShell loaders through custom decoders. Notable evolution includes anti-analysis routines detecting virtualization tools, Pastebin as alternative C2 infrastructure, and diversified decoy formats (PDF, XLSX, PNG). Metadata analysis reveals AI-generated content using the 'opencode' AI coding agent and HeadlessChrome PDF conversion, with placeholder text remaining unreviewed. The group maintains persistence through hidden scheduled tasks masquerading as legitimate software (BitLocker, MATLAB), while hardcoded GitHub PATs enable raw content retrieval. Despite increased sophistication in evasion techniques and decoy production automation, endpoint behaviors remain detectable through behavioral correlation a...
Pulse ID: 6a9e70fd7eb74853a795cc57
Pulse Link: https://otx.alienvault.com/pulse/6a9e70fd7eb74853a795cc57
Pulse Author: AlienVault
Created: 2026-09-07 08:08:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Chrome #CyberSecurity #Endpoint #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #PDF #PowerShell #RAT #UK #bot #AlienVault
-
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
The Kimsuky threat group continues Operation GitPower campaigns utilizing malicious LNK files disguised as financial and business documents. Thirteen LNK variants collected between August 11-19, 2026, employ GitHub Personal Access Tokens (PAT) for command-and-control communications, delivering obfuscated PowerShell loaders through custom decoders. Notable evolution includes anti-analysis routines detecting virtualization tools, Pastebin as alternative C2 infrastructure, and diversified decoy formats (PDF, XLSX, PNG). Metadata analysis reveals AI-generated content using the 'opencode' AI coding agent and HeadlessChrome PDF conversion, with placeholder text remaining unreviewed. The group maintains persistence through hidden scheduled tasks masquerading as legitimate software (BitLocker, MATLAB), while hardcoded GitHub PATs enable raw content retrieval. Despite increased sophistication in evasion techniques and decoy production automation, endpoint behaviors remain detectable through behavioral correlation a...
Pulse ID: 6a9e70fd7eb74853a795cc57
Pulse Link: https://otx.alienvault.com/pulse/6a9e70fd7eb74853a795cc57
Pulse Author: AlienVault
Created: 2026-09-07 08:08:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Chrome #CyberSecurity #Endpoint #GitHub #InfoSec #Kimsuky #LNK #OTX #OpenThreatExchange #PDF #PowerShell #RAT #UK #bot #AlienVault
-
Recent Kimsuky spear phishing campaigns abuse remote control tools and AI extensions to target victims in Japan and South Korea. Read the full analysis.
#Kimsuky #CyberSecurity #SpearPhishing #Malware #ThreatIntel
-
ENKI WhiteHat found Kimsuky abusing legitimate tools like Chrome Remote Desktop and AnyDesk for stealthy persistence in phishing campaigns against South Korea and Japan.
#Kimsuky #ChromeRemoteDesktop #AnyDesk #Phishing #NorthKorea
-
North Korea Deploys AI-Built Chrome Extension to Steal Gmail
Kimsuky hackers used an AI-generated Chrome extension that automatically exfiltrates Gmail messages and attachments to North Korean servers
https://pulseofnations.lol/north-korea-deploys-ai/
#AI #ChromeExtension #Gmail #Kimsuky #NorthKorea #Phishing #StateSponsored
-
Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia
Pulse ID: 6a8d193e166f33d196fc97b8
Pulse Link: https://otx.alienvault.com/pulse/6a8d193e166f33d196fc97b8
Pulse Author: Tr1sa111
Created: 2026-08-25 04:25:34Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CyberSecurity #InfoSec #Kimsuky #OTX #OpenThreatExchange #UK #bot #Tr1sa111
-
Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia
Pulse ID: 6a87f297285ce48e4e1d19fc
Pulse Link: https://otx.alienvault.com/pulse/6a87f297285ce48e4e1d19fc
Pulse Author: Tr1sa111
Created: 2026-08-21 06:39:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CyberSecurity #InfoSec #Kimsuky #OTX #OpenThreatExchange #UK #bot #Tr1sa111
-
Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia
Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.
Pulse ID: 6a873495a873c0ec3c6d9880
Pulse Link: https://otx.alienvault.com/pulse/6a873495a873c0ec3c6d9880
Pulse Author: AlienVault
Created: 2026-08-20 17:08:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault
-
Kimsuky AI operations reveal a North Korea threat actor testing local LLMs. Suspected state hackers are building new capabilities to automate phishing.
#Kimsuky #CyberSecurity #LLM #NorthKorea #ThreatActor #Genians
https://securityonline.info/kimsuky-ai-operations/?utm_source=mastodon&utm_medium=jetpack_social
-
Integrating AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM
The Kimsuky threat group has integrated artificial intelligence capabilities into its attack operations, establishing local large language model environments using Ollama, GPT4All, and Msty. Evidence indicates the group is accumulating technologies to incorporate AI across attack operations, including AI-generated decoy documents and retrieval-augmented generation for document analysis. The campaign, dubbed Operation GitPower, continues targeting foreign diplomatic missions and sectors including military, security, and virtual assets. Attacks utilize malicious LNK files contained in ZIP archives, executing obfuscated PowerShell scripts that abuse Git-based repositories as command-and-control infrastructure. The group distributes encrypted AsyncRAT payloads disguised as image files through GitHub. Linguistic indicators including North Korean vocabulary patterns such as "싸이트", "가입리력", and "로출되였는지" support attribution to North Korean state-sponsored operations under the Reconnaissance General Bureau.
Pulse ID: 6a79d612a1f9e2ac4e744aa8
Pulse Link: https://otx.alienvault.com/pulse/6a79d612a1f9e2ac4e744aa8
Pulse Author: AlienVault
Created: 2026-08-10 13:45:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AsyncRAT #CyberSecurity #GitHub #InfoSec #Kimsuky #Korea #LNK #Military #NorthKorea #OTX #OpenThreatExchange #PowerShell #RAT #UK #ZIP #bot #AlienVault
-
Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant
#Kimsuky #HttpSpy
https://www.enki.co.kr/en/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant -
Interesting technique. Obfuscates its string decoder inside android namespace "com .google .android .material .timepicker". That helper XOR-decodes which then concatenates into the C2: http://95.164.86[.]148/dash/index[.]php. #kimsuky
-
North Korean Kimsuky Actors Leverage Malicious QR Codes in Spearphishing Campaigns Targeting U.S. Entities
#Kimsuky
https://www.ic3.gov/CSA/2026/260108.pdf -
FBI: North Korean Spear-Phishing Attacks Use Malicious QR Codes https://www.securityweek.com/fbi-north-korean-spear-phishing-attacks-use-malicious-qr-codes/ #Malware&Threats #spear-phishing #NorthKorea #quishing #Kimsuky #QRcode #FBI
-
📬 Zehntausende ASUS-Router sind unter fremder Kontrolle
#Cyberangriffe #ITSicherheit #AiCloud #AsusRouter #AyySSHush #Kimsuky #Lazarus #ORBKnoten #WrtHug https://sc.tarnkappe.info/90a693 -
Hackers Use KakaoTalk and Google Find Hub in Android Spyware Attack https://hackread.com/hackers-kakaotalk-google-find-hub-android-spyware/ #ScamsandFraud #Cybersecurity #GoogleFundHub #CyberAttack #NorthKorea #SouthKorea #KakaoTalk #Security #Android #Malware #Kimsuky #APT37 #Konni
-
New Kimsuky Malware “EndClient RAT”: First Technical Report and IOCs
#Kimsuky #EndClientRAT
https://www.0x0v1.com/endclientrat/ -
New Kimsuky Malware “EndClient RAT”: First Technical Report and IOCs
-
Generative-AI deepfakes + runtime command reconstruction = AV bypass. Kimsuky used ChatGPT images + environment-variable slicing to assemble malicious PowerShell/AutoIt chains and persist via scheduled tasks.
Recommend EDR behavioral rules for script reconstruction, scheduled-task anomalies, and staged HTTP fetch chains. Discuss & follow @technadu
#CyberSecurity #AI #Deepfakes #Phishing #EDR #ThreatIntel #Kimsuky #InfoSec
-
🇰🇵 Severokorejská skupina Kimsuky využívá ChatGPT k výrobě falešných průkazů pro phishing.
🇰🇵 The North Korean group Kimsuky uses ChatGPT to produce fake IDs for phishing.
-
North Korea’s #Kimsuky hackers are using AI-generated fake military IDs, reportedly created with ChatGPT, to lure victims in their latest phishing campaign.
Read: https://hackread.com/north-korea-kimsuky-group-ai-generated-military-ids/
-
Kimsuky Hackers’ Playbook Uncovered in Exposed ‘Kim’ Data Dump https://gbhackers.com/kimsuky-hackers/ #CyberSecurityNews #cybersecurity #Kimsuky
-
How the "Kim" dump exposed North Korea's credential theft playbook
#HackerNews #KimDump #NorthKorea #CredentialTheft #CyberSecurity #HackerNews #Kimsuky
-
Inside the Kimsuky Leak: How the “Kim” Dump Exposed North Korea’s Credential Theft Playbook
#Kimsuky
https://dti.domaintools.com/inside-the-kimsuky-leak-how-the-kim-dump-exposed-north-koreas-credential-theft-playbook/ -
🔥The "Kim" leak is an intelligence goldmine.
For analysts: We’ve got an unprecedented look into a DPRK threat actor's playbook. This isn't just about known tactics like credential theft and phishing. Our analysis shows a strategic pivot to include Taiwanese developer and government networks, revealing a clear geographical expansion of North Korea's cyber interests.
For defenders: We've mapped the full scope of this threat—from custom Linux rootkits to particular targets like PKI infrastructure and specific tools like NASM and ocrmypdf. Our report provides defensive recommendations and specific Indicators of Compromise (IOCs), so your team can detect and block this persistent, infrastructure-centric campaign.
Get the full technical breakdown and all the IOCs in our new post.
#ThreatIntelligence #Cybersecurity #NationStateAPT #Kimsuky #ThreatAnalysis #DFIR #InfoSec