North Korea-Linked Hackers Use GitHub as C2 Infrastructure to Attack South Korea
2026-04-08 • Excalibra •
FortiGuard Labs identifies a Kimsuky campaign targeting South Korean organizations through phishing-delivered LNK files that abuse GitHub as command-and-control infrastructure. The LNK files display decoy PDFs while running obfuscated PowerShell that performs anti-analysis checks, creates scheduled-task persistence, collects host data, and exfiltrates logs to attacker-controlled GitHub repositories. The same repositories are used to host commands and additional modules, with hardcoded access tokens and accounts such as motoralis, God0808RAMA, Pigresy80, entire73, pandora0009, and brandonleeodd93-blip cited as infrastructure. The excerpt connects the activity to earlier GitHub-based Xeno RAT and MoonPeak reporting and notes a related AhnLab-observed Kimsuky chain that uses Dropbox and ZIP fragments to deploy a Python backdoor. The operational significance is the continued DPRK-linked shift toward trusted platforms, native Windows tooling, and scheduled tasks to reduce detection and sustain access.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | af0309aa38d067373c54b2a7774a32f… | 2026-04-02 | 2026-04-08 |
| HASH | f20fde3a9381c22034f7ecd4fef2396… | 2026-04-02 | 2026-04-08 |
| HASH | c0866bb72c7a12a0288f434e16ba14e… | 2026-04-02 | 2026-04-08 |
| HASH | 9c3f2bd300ad2ef8584cc48adc47aab… | 2026-04-02 | 2026-04-08 |
| HASH | 484a16d779d67c7339125ceac10b9ab… | 2026-04-02 | 2026-04-08 |