North Korea Uses GitHub as C2 in New LNK Phishing Campaign
ID: fcd88af4-bedf-5cf1-9bb5-ad33c78707f2
STIX ID: report--fcd88af4-bedf-5cf1-9bb5-ad33c78707f2
Feed Name: GBHackers
FortiGuard Labs documents a DPRK-linked phishing campaign targeting users in South Korea that uses malicious LNK shortcuts containing embedded decoy PDFs and encoded payloads; the LNKs drop and execute PowerShell/VBScript loaders which perform environment checks, establish persistence via Scheduled Tasks, and use GitHub repositories and API tokens as a stealthy HTTPS-based C2 and exfiltration channel, with overlaps across multiple attacker-owned GitHub accounts and a potential follow-on delivery of XenoRAT.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
