logo

DPRK-Linked Hackers Use GitHub as C2 in Multi-Stage Attacks Targeting South Korea

ID: 65ad3248-964b-599f-8c06-c7bc3fa1a955

STIX ID: report--65ad3248-964b-599f-8c06-c7bc3fa1a955

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-04-06

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers observed DPRK-associated threat actors conducting multi-stage attacks against South Korean organizations using obfuscated LNK files to drop decoy documents and PowerShell scripts that establish persistence, perform anti-analysis checks, profile hosts, and exfiltrate data to attacker-controlled GitHub repositories; variants of the campaign also use Dropbox and remote servers to deliver Python-based backdoors (Xeno RAT, MoonPeak, RokRAT) and employ DLL side-loading and OLE-based droppers for delivery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.