DPRK-Related Campaigns with LNK and GitHub C2

2026-04-02 Fortinet

https://www.fortinet.com/blog/threat-research/dprk-related-campaigns-with-lnk-and-github-c2

Thumbnail for DPRK-Related Campaigns with LNK and GitHub C2

FortiGuard Labs observed DPRK-related LNK phishing campaigns targeting users in South Korea and other Korean companies through multi-stage PowerShell and VBScript execution on Windows. Earlier variants exposed metadata and GitHub command-and-control details tied to XenoRAT activity, while newer LNK files embed decoding functions and encoded payloads directly in arguments to reduce obvious indicators. The infection chain drops a matching decoy PDF, checks for virtual machine, debugger, and forensic tools, writes payloads into randomly named Temp folders, and creates a hidden scheduled task that re-runs VBScript every 30 minutes. The scripts collect operating system, process, boot-time, IP, and network information, upload logs through the GitHub API, and fetch additional instructions from GitHub repositories controlled by accounts including motoralis. The campaign matters because it combines native Windows tools, phishing themes, GitHub private repositories, and trusted GitHub traffic to maintain persistence and exfiltrate victim data with low visibility.

Indicators of Compromise

Type Value First Seen Last Seen
HASH af0309aa38d067373c54b2a7774a32f… 2026-04-02 2026-04-08
HASH f20fde3a9381c22034f7ecd4fef2396… 2026-04-02 2026-04-08
HASH c0866bb72c7a12a0288f434e16ba14e… 2026-04-02 2026-04-08
HASH 9c3f2bd300ad2ef8584cc48adc47aab… 2026-04-02 2026-04-08
HASH 484a16d779d67c7339125ceac10b9ab… 2026-04-02 2026-04-08

Related Reports

« Back