Kimsuky-linked Operation GitPower activity distributed at least 13 malicious .LNK files in ZIP archives through spearphishing, posing as finance, insurance, payment, and retail business documents. The shortcuts execute obfuscated PowerShell loaders that use a GitHub personal access token (PAT) to retrieve decoy files and subsequent payloads from GitHub Raw Content; one Visa5499 variant also used Pastebin as a second-stage delivery channel.
The malware establishes persistence through hidden scheduled tasks disguised as legitimate software, can delete itself and PowerShell history, and checks for analysis tools, virtual-machine processes, and sandbox usernames before execution. Downloaded PDF decoys contained opencode metadata, matching creation timestamps, unreplaced temporary-value placeholders, and HeadlessChrome/Skia artifacts, suggesting an automated AI/LLM-assisted lure-production workflow. Defenders should correlate LNK-launched PowerShell, unusually long whitespace-padded command lines, .ps1 creation in AppData or Temp, masqueraded scheduled tasks, and GitHub PAT or Pastebin communications.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
A Bluesky post citing an ESTSecurity report described purported new Kimsuky-associated LNK malware and stated that the group operates command-and-control servers separated by function. The post provided no victims, indicators, domains, payload details, or confirmed targeting information.
Four recovered PDF decoys recorded opencode as their Creator and Producer and anonymous as Author; all four had a creation timestamp of 2026-08-16 03:00:00 UTC. The documents also retained an unfilled Korean “(temporary value)” placeholder, supporting an assessment that AI/LLM-enabled automation was used to produce lures.
Genian Security Center analyzed 13 malicious LNK files collected between August 11 and 19 and assessed the activity as a Kimsuky-linked Operation GitPower campaign. The files were distributed in spearphishing ZIP archives impersonating financial, insurance, payment, and corporate-business documents.
An Alyac analysis assessed a Korean financial-PDF-themed LNK campaign as likely Kimsuky-linked. The malware used staged BAT scripts, five-minute scheduled-task persistence, GitHub-hosted commands keyed to each victim's MachineGuid, a Wasmer WordPress endpoint for infection notification, and Dropbox APIs for reconnaissance exfiltration; selected victims could receive a Pinggy reverse-tunnel payload.
Analysts recovered 29 decoy files but found only 11 unique documents by MD5, indicating that Kimsuky operators reused decoy content under randomized filenames. The analysis also published campaign-linked GitHub accounts, email addresses, and malicious LNK sample hashes.
A customer-document LNK variant checked virtualization and analysis-tool processes, stopped execution for the username Bruno, and deleted PowerShell command history before presenting an XLSX decoy. The Visa5499 variant used GitHub to obtain a PNG lure but downloaded code from Pastebin for in-memory execution, diversifying its second-stage delivery path.
Observed LNK variants launched obfuscated PowerShell loaders, saved decrypted second-stage scripts under randomly named AppData PS1 files, and retrieved decoy documents and follow-on payloads from GitHub Raw Content using a hard-coded GitHub personal access token. One variant established persistence through a disguised scheduled task named after BitLocker.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 31 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
10 references tracked. Mallory keeps watching after this page renders.
bsky.app
Open sourceblog.alyac.co.kr
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcebsky.app
Open sourcemalware.news
Open sourcegenians.co.kr
Open sourcegenians.co.kr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.