North Korean Hackers Abuse GitHub to Spy on South Korean Firms
ID: f0d7c6de-572c-571e-91cb-2e066488e88a
STIX ID: report--f0d7c6de-572c-571e-91cb-2e066488e88a
Feed Name: HackRead
Threat Score
FortiGuard Labs reports a high-severity North Korean espionage campaign targeting South Korean companies that uses LNK shortcut files and native Windows utilities (PowerShell, VBScript, scheduled tasks) to execute hidden scripts, avoid detection, and exfiltrate system information via legitimate GitHub repositories; attributed to groups such as Kimsuky, APT37 or Lazarus, the campaign emphasizes living-off-the-land TTPs and covert persistence rather than overt malware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
