GitHub-Backed Malware Spread via LNK Files in South Korea
ID: b13fac77-83cf-5985-9020-fe83485cf724
STIX ID: report--b13fac77-83cf-5985-9020-fe83485cf724
Feed Name: GBHackers
This report details a stealthy, multi-stage malware campaign targeting organizations in South Korea that uses weaponized LNK files to execute obfuscated PowerShell and VBScript payloads, registers hidden Scheduled Tasks for persistence, performs anti-analysis and environment checks, and uses private GitHub repositories and API tokens as a resilient C2 and exfiltration channel; researchers traced activity to multiple GitHub accounts and advise tightening monitoring of LNK/doc files, PowerShell/wscript activity, and GitHub API usage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
