North Korean Actors Exploit GitHub in Multi-Stage Malware Campaign Against South Korea
ID: f3880550-df4c-5dd6-9493-9d7a8550554f
STIX ID: report--f3880550-df4c-5dd6-9493-9d7a8550554f
Feed Name: ThreatCluster
Threat Score
A sophisticated multi-stage malware campaign attributed to North Korean state actors targets South Korean users by delivering malicious LNK files that execute hidden PowerShell scripts and decoy PDFs; the campaign uses GitHub as covert command-and-control to download additional payloads, maintain persistence, and exfiltrate data, and recent variants have removed identifying metadata and added stronger obfuscation to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
