DPRK-Linked Hackers Use GitHub as C2 in Multi-Stage Attacks Targeting South Korea
ID: 65ad3248-964b-599f-8c06-c7bc3fa1a955
STIX ID: report--65ad3248-964b-599f-8c06-c7bc3fa1a955
Feed Name: The Hacker News
Researchers observed DPRK-associated threat actors conducting multi-stage attacks against South Korean organizations using obfuscated LNK files to drop decoy documents and PowerShell scripts that establish persistence, perform anti-analysis checks, profile hosts, and exfiltrate data to attacker-controlled GitHub repositories; variants of the campaign also use Dropbox and remote servers to deliver Python-based backdoors (Xeno RAT, MoonPeak, RokRAT) and employ DLL side-loading and OLE-based droppers for delivery.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
