DPRK-Related Campaigns with LNK and GitHub C2
2026-04-02 • Fortinet •
https://www.fortinet.com/blog/threat-research/dprk-related-campaigns-with-lnk-and-github-c2
FortiGuard Labs observed DPRK-related LNK phishing campaigns targeting users in South Korea and other Korean companies through multi-stage PowerShell and VBScript execution on Windows. Earlier variants exposed metadata and GitHub command-and-control details tied to XenoRAT activity, while newer LNK files embed decoding functions and encoded payloads directly in arguments to reduce obvious indicators. The infection chain drops a matching decoy PDF, checks for virtual machine, debugger, and forensic tools, writes payloads into randomly named Temp folders, and creates a hidden scheduled task that re-runs VBScript every 30 minutes. The scripts collect operating system, process, boot-time, IP, and network information, upload logs through the GitHub API, and fetch additional instructions from GitHub repositories controlled by accounts including motoralis. The campaign matters because it combines native Windows tools, phishing themes, GitHub private repositories, and trusted GitHub traffic to maintain persistence and exfiltrate victim data with low visibility.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | af0309aa38d067373c54b2a7774a32f… | 2026-04-02 | 2026-04-08 |
| HASH | f20fde3a9381c22034f7ecd4fef2396… | 2026-04-02 | 2026-04-08 |
| HASH | c0866bb72c7a12a0288f434e16ba14e… | 2026-04-02 | 2026-04-08 |
| HASH | 9c3f2bd300ad2ef8584cc48adc47aab… | 2026-04-02 | 2026-04-08 |
| HASH | 484a16d779d67c7339125ceac10b9ab… | 2026-04-02 | 2026-04-08 |