logo

DPRK hackers dupe targets into typing PowerShell commands as admin

ID: 6e1f05d6-67f5-52fb-bb3c-6312beede6c6

STIX ID: report--6e1f05d6-67f5-52fb-bb3c-6312beede6c6

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2025-02-12

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Microsoft observed North Korean state actor Kimsuky adopting ClickFix-style social engineering to persuade targets to run attacker-provided PowerShell as administrator; the resulting script installs a browser-based remote desktop, retrieves a certificate via a hardcoded PIN, and registers the victim device with a remote server to enable direct access and data exfiltration. These limited-scope spear-phishing attacks, delivered via PDFs with fake device-registration links, have targeted international affairs, NGOs, government agencies, and media across multiple regions since January 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.