logo

GitHub Used as Covert Channel in Multi-Stage Malware Campaign

ID: 1608ec7d-84f9-5375-a67c-e6d56f6a24f7

STIX ID: report--1608ec7d-84f9-5375-a67c-e6d56f6a24f7

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-04-02

Date Updated: 2026-04-22

...
...

Malicious LNK files targeting users in South Korea use a multi-stage, living-off-the-land campaign that embeds encoded payloads and PowerShell scripts (retrieved from or communicating with GitHub) to execute silently, drop decoy PDFs, establish persistence via scheduled tasks, and exfiltrate system information; recent variants reduce metadata and embed decoding to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.