DPRK (Kimsuky) Multi-Stage LNK Phishing Campaign Delivering XenoRAT via GitHub-based C2 Targeting South Korea — Threadlinqs Intelligence
As of 2026-08-06, DPRK (Kimsuky) Multi-Stage LNK Phishing Campaign Delivering XenoRAT via GitHub-based C2 Targeting South Korea is a high-severity malware threat attributed to Kimsuky (North Korea), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-0771 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Updated: 2026-08-06
Attribution: Kimsuky · North Korea · ESPIONAGE
FortiGuard Labs documented an active North Korean (Kimsuky-attributed) campaign that delivers obfuscated Windows LNK files disguised as Korean PDF proposals, which drop a decoy PDF and run hidden,
FortiGuard Labs identified a series of malicious Windows shortcut (LNK) files targeting users and organizations in South Korea as part of an ongoing DPRK state-sponsored espionage campaign attributed to Kimsuky, with TTP overlaps to APT37/ScarCruft and broader Lazarus-pattern activity. The LNK files masquerade as Korean-language business and diplomatic PDF documents (e.g. strategic partnership proposals, investment fund offers, and an 'Urgent Letter from the Ambassador, Embassy of Poland'), using the .pdf.lnk double-extension and 'Hangul Document' naming patterns characteristic of North Korean operators.
When executed, the LNK opens a decoy PDF to allay suspicion while silently launching an obfuscated PowerShell payload. The PowerShell stage performs anti-analysis reconnaissance, enumerating running processes for virtual-machine artifacts (vmtoolsd, vboxservice), debuggers and reverse-engineering tools (x64dbg, OllyDbg, IDA, dnSpy, de4dot, ImmunityDebugger), and network/forensic analysis utilities (Wireshark, Fiddler, Procmon, ProcessHacker, TCPView); if any are present, execution terminates immediately. Surviving hosts have a VBScript dropped and registered as a scheduled task (using decoy names such as 'Technical Paper for Creata Chain Task...' and 'SysUpdate') that re-launches the PowerShell payload in a hidden window every 30 minutes via wscript.exe, providing persistence across reboots.
The campaign's defining innovation is the use of GitHub as C2. The malware authenticates to the GitHub REST API with hard-coded personal access tokens and pulls additional staged payloads and operator instructions from attacker-controlled repositories (notably the 'motoralis/singled' repo, e.g. raw.githubusercontent.com/motoralis/singled/main/kcca/paper.jim and api.github.com/repos/motoralis/singled/contents/kcca/technik), while uploading exfiltrated host profiles and beacon logs back to the repo (e.g. jjyun/network/<Date>_<Time>-<IP>-Real.log). Multiple sock-puppet GitHub accounts (motoralis, God0808RAMA, Pigresy80, entire73, pandora0009, brandonleeodd93-blip) support the operation. The final payload is XenoRAT (open-source .NET RAT), consistent with prior Kimsuky GitHub-C2 deployments of XenoRAT and its MoonPeak variant documented by ENKI and Trellix in 2025. The actor's heavy reliance on living-off-the-land binaries (LOLBins) and a legitimate cloud service for C2 yields a low detection footprint, making behavioral and network-egress detection essential for defenders.
Target sectors: government, diplomatic, financial, cryptocurrency, technology, think-tanks
Target regions: South Korea, East Asia
Update History
- 2026-08-06 — tweetfeed.live community intel: New TL_OSINT_Scan community intel: 1 newly-corroborated indicator(s), 62 community-related indicator(s).
Detections & IOCs
As of 2026-08-17, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1204, T1059, T1053, T1547, T1037, T1140, T1027, T1036, T1497