logo

GitHub-Backed Malware Spread via LNK Files in South Korea

ID: b13fac77-83cf-5985-9020-fe83485cf724

STIX ID: report--b13fac77-83cf-5985-9020-fe83485cf724

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-04-06

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

This report details a stealthy, multi-stage malware campaign targeting organizations in South Korea that uses weaponized LNK files to execute obfuscated PowerShell and VBScript payloads, registers hidden Scheduled Tasks for persistence, performs anti-analysis and environment checks, and uses private GitHub repositories and API tokens as a resilient C2 and exfiltration channel; researchers traced activity to multiple GitHub accounts and advise tightening monitoring of LNK/doc files, PowerShell/wscript activity, and GitHub API usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.