DPRK hackers dupe targets into typing PowerShell commands as admin
ID: 6e1f05d6-67f5-52fb-bb3c-6312beede6c6
STIX ID: report--6e1f05d6-67f5-52fb-bb3c-6312beede6c6
Feed Name: Bleeping Computer
Microsoft observed North Korean state actor Kimsuky adopting ClickFix-style social engineering to persuade targets to run attacker-provided PowerShell as administrator; the resulting script installs a browser-based remote desktop, retrieves a certificate via a hardcoded PIN, and registers the victim device with a remote server to enable direct access and data exfiltration. These limited-scope spear-phishing attacks, delivered via PDFs with fake device-registration links, have targeted international affairs, NGOs, government agencies, and media across multiple regions since January 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
