North Korea-Linked Hackers Use GitHub as C2 Infrastructure to Attack South Korea

2026-04-08 Excalibra

https://medium.com/bugbountywriteup/north-korea-linked-hackers-use-github-as-c2-infrastructure-to-attack-south-korea-1bdcbaf9a9d8

Thumbnail for North Korea-Linked Hackers Use GitHub as C2 Infrastructure to Attack South Korea

FortiGuard Labs identifies a Kimsuky campaign targeting South Korean organizations through phishing-delivered LNK files that abuse GitHub as command-and-control infrastructure. The LNK files display decoy PDFs while running obfuscated PowerShell that performs anti-analysis checks, creates scheduled-task persistence, collects host data, and exfiltrates logs to attacker-controlled GitHub repositories. The same repositories are used to host commands and additional modules, with hardcoded access tokens and accounts such as motoralis, God0808RAMA, Pigresy80, entire73, pandora0009, and brandonleeodd93-blip cited as infrastructure. The excerpt connects the activity to earlier GitHub-based Xeno RAT and MoonPeak reporting and notes a related AhnLab-observed Kimsuky chain that uses Dropbox and ZIP fragments to deploy a Python backdoor. The operational significance is the continued DPRK-linked shift toward trusted platforms, native Windows tooling, and scheduled tasks to reduce detection and sustain access.

Indicators of Compromise

Type Value First Seen Last Seen
HASH af0309aa38d067373c54b2a7774a32f… 2026-04-02 2026-04-08
HASH f20fde3a9381c22034f7ecd4fef2396… 2026-04-02 2026-04-08
HASH c0866bb72c7a12a0288f434e16ba14e… 2026-04-02 2026-04-08
HASH 9c3f2bd300ad2ef8584cc48adc47aab… 2026-04-02 2026-04-08
HASH 484a16d779d67c7339125ceac10b9ab… 2026-04-02 2026-04-08

Related Actors

Related Reports

« Back