logo

New Phishing Campaign Abuses GitHub to Target South Korea

ID: b5bbd9ee-ab57-5e6d-86eb-7925c9be0271

STIX ID: report--b5bbd9ee-ab57-5e6d-86eb-7925c9be0271

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-09

Date Updated: 2026-04-23

Author: Ddos

...
...

FortiGuard Labs describes a sophisticated cyberespionage campaign targeting South Korea that uses phishing LNK files to deploy multi-stage scripts (VBScript → PowerShell) and leverages the GitHub API as covert C2; prior payloads have included the XenoRAT remote access trojan. The operation favors living-off-the-land techniques and trusted public infrastructure to evade detection, and the report includes lure document titles, the infection chain, and recommendations to monitor unusual PowerShell/VBScript activity and communications with public repositories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.