Researchers linked a North Korean Kimsuky intrusion cluster to spearphishing campaigns that deliver ZIP archives containing malicious .lnk files, which launch obfuscated PowerShell, open decoy PDF documents, and create persistence through scheduled tasks. The activity, tracked by Genians as Operation GitPower, also used public GitHub and GitLab repositories as command-and-control channels and malware staging infrastructure, including encrypted .NET AsyncRAT payloads disguised as image files. Fortinet separately reported DPRK-linked campaigns using the same combination of LNK-based infection chains and GitHub-backed C2, reinforcing the pattern across related operations.
Investigators said the operators appear to be expanding beyond conventional malware delivery and are actively experimenting with AI-enabled tradecraft. Artifacts showed local LLM environments built with tools including Ollama, GPT4All, and Msty, along with RAG-style document handling, AI agent development libraries, and Whisper speech-to-text components, suggesting a research-and-integration phase focused on malware development, document analysis, and attack automation rather than training original models. Attribution was supported by overlaps with prior Kimsuky techniques, Korean-language artifacts, North Korean lexical patterns, Arirang manufacturer strings, and use of Astrill VPN.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
On August 9, 2026, Genians Security Center published a threat intelligence report detailing Operation GitPower and attributing it to Kimsuky. The report documented the campaign's spearphishing, GitHub/GitLab-based C2, RC4-encrypted AsyncRAT staging, AI-generated lures, and local LLM tooling artifacts.
The report says the threat actor used AI-generated lure PDFs in 2026 with cryptocurrency, finance, and game-development themes. Two English lure PDFs shared metadata indicating creation with python-docx and WPS 文字.
One analyzed infection chain wrote a PowerShell script to the TEMP directory, downloaded a decoy PDF from GitHub Raw Content, and opened it to distract the victim. It then created additional scripts under AppData and registered a hidden scheduled task for persistence and recurring execution.
On July 17, 2025, Genians detected a spearphishing attack impersonating a South Korean defense-related institution and using AI-generated deepfake military ID card images as lures. The campaign used a ZIP-delivered malicious LNK, obfuscated PowerShell and batch scripts, and infrastructure including jiwooeng.co[.]kr and liveml.cafe24[.]com, and was linked to related June 2025 ClickFix-style phishing activity.
On February 7, 2024, the U.S. Department of the Treasury announced sanctions targeting North Korean international agents and an illicit cyber intrusion group. The action represented an official U.S. government response to DPRK-linked cyber activity.
Researchers found evidence that the operators installed and used local AI tooling including Ollama, GPT4All, and Msty, along with LocalDocs/RAG-style components and speech-to-text tooling. They also collected AI development libraries such as Semantic Kernel, Microsoft.Agents.AI, OpenAI, Azure.AI.OpenAI, and LangChain-related packages.
Researchers observed the operators using public Git repositories both as command-and-control infrastructure and to distribute RC4-encrypted .NET AsyncRAT payloads disguised as image files such as apple.png, fox.png, lion.png, rabbit.png, and wolf.png. Some samples exposed test and operational C2 IP addresses, including 169.254.33[.]137 and 112.216.9[.]171.
The campaign used spearphishing emails carrying ZIP archives that contained malicious LNK shortcut files disguised as legitimate documents such as embassy correspondence, legal documents, and payment requests. When opened, the LNKs launched heavily obfuscated PowerShell.
Genians tracked a long-running intrusion cluster using GitHub and GitLab infrastructure and assessed it as associated with the North Korean Kimsuky group. The activity targeted foreign embassies and organizations in military, security, and cryptocurrency-related sectors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcefortinet.com
Open sourcegenians.co.kr
Open sourcehome.treasury.gov
Open sourcegenians.co.kr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.