logo

DPRK-Related Campaigns with LNK and GitHub C2

ID: 1b2e6520-85fe-5714-be64-d5742ada5942

STIX ID: report--1b2e6520-85fe-5714-be64-d5742ada5942

Feed Name: Fortinet Blog

Threat Score
78/100

Date Published: 2026-04-02

Date Updated: 2026-04-27

...
...

FortiGuard Labs describes a high-severity LNK-based phishing campaign targeting organizations in South Korea that leverages obfuscated LNK arguments and embedded Base64/XOR-encoded payloads to execute PowerShell and VBScript, perform anti-analysis checks, establish scheduled-task persistence, and exfiltrate system and network data to GitHub (including repositories and raw content URLs). The actor uses GitHub API calls and hardcoded tokens as C2/exfiltration channels, minimizes dropped PE files by abusing native Windows tools, and the report includes multiple IOCs (GitHub URLs and SHA256 LNK file hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.