logo

North Korea-Related Campaign Abuses GitHub as C2 in New LNK Phishing Attacks

ID: 9fd569d6-d0fb-538d-a732-84a55d81baec

STIX ID: report--9fd569d6-d0fb-538d-a732-84a55d81baec

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-04-03

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A North Korean state-sponsored campaign uses weaponized Windows LNK shortcut files that decode and execute PowerShell/VBScript payloads, display decoy PDFs, and use private GitHub repositories as covert C2 and exfiltration channels to conduct long-term surveillance of South Korean organizations; persistence is achieved via scheduled tasks and the campaign shows evolving obfuscation and targeted lure documents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.