Kimsuky APT Targets Crypto Users and Defense Officials With LNK Lures
ID: e2c14983-cf83-5020-9cb5-c5f6b0d9e9cd
STIX ID: report--e2c14983-cf83-5020-9cb5-c5f6b0d9e9cd
Feed Name: Cyber Press
Kimsuky, a North Korean state-linked APT, ran multiple highly sophisticated spear-phishing campaigns in early 2026 targeting cryptocurrency investors, defense officials, corporate recruiters, and academic staff. Attackers used deceptive LNK and JSE files to drop information-stealing malware that exfiltrated data via raw GitHub URLs and established covert remote access by abusing the official VSCode tunneling and OAuth device tokens; they also employed living-off-the-land techniques (certutil, schtasks, scheduled tasks), decoy files, and obfuscated PowerShell for persistence and evasion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
