Threat reportAPTTL-2026-2005
Kimsuky 'Operation GitPower' Integrates Local AI Tooling into AsyncRAT Espionage Campaign
Kimsuky 'Operation GitPower' Integrates Local AI Tooling (TL-2026-2005), also tracked as Operation GitPower, is a high-severity advanced persistent threat campaign, first published 2026-08-13. It is attributed to Kimsuky (North Korea) with high confidence, affects Microsoft Windows (LNK, PowerShell, and Task Scheduler execution, maps to 13 MITRE ATT&CK techniques (T1007, T1010, T1027), and is covered by 9 detection rules and 27 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 13MITRE ATT&CK
- Actors
- 1Kimsuky
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 27Indicators of compromise
Key facts for TL-2026-2005
- Threat ID
- TL-2026-2005
- Also known as
- Operation GitPower
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- Kimsuky
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- ESPIONAGE
- Target sectors
- government administration, diplomatic, military, defense, virtual-asset, cryptocurrency, financial-services, policy-research, academic
- Target regions
- south korea, Global (diplomatic missions)
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in Kimsuky 'Operation GitPower' Integrates Local AI Tooling
Malware and tooling: AsyncRAT, lnkbuilder.exe
How Kimsuky 'Operation GitPower' Integrates Local AI Tooling works
North Korean state-sponsored actor Kimsuky is running Operation GitPower, a spear-phishing campaign against diplomatic missions, military/security organizations, policy and academic communities, and the virtual-asset sector, using an LNK-to-PowerShell infection chain and GitHub-hosted repositories as a C2 channel to deliver RC4-encrypted .NET AsyncRAT payloads disguised as image files. Genians (original discloser) found the same servers running an offline local-LLM stack (Ollama, GPT4All with a configured LocalDocs RAG database, Msty) plus AI development tooling (Cursor, LLaMaSharp, Microsoft Semantic Kernel, Whisper) that the operator is using to author AI-generated decoy documents and prototype document-analysis/automation workflows against stolen material.
Genians (2026-08-10) documents Operation GitPower as a continuation of long-running Kimsuky spear-phishing activity rather than a new campaign. Victims receive ZIP archives containing a malicious LNK disguised as a business document (honorarium requests, embassy correspondence, investment strategy packs). The LNK carries an ~3,800-character embedded PowerShell command padded with roughly 300 consecutive spaces and false shortcut metadata to hide its content from casual inspection, and decodes its payload with a custom bitwise Base64 routine rather than a standard cmdlet. The first-stage script fetches a decoy PDF from the GitHub Raw Content API (URL assembled via string concatenation to evade static string matching), displays it to the victim, and in the background writes an intermediate script to %AppData%\irujkdnjhgttrhdkfdu.ps1. Persistence is established via a hidden Scheduled Task with a randomized all-caps name (e.g. ZHUYHJGTYTFSUHIPOKLKHJHUYGVHGNFH) that fires ~5 minutes after registration and then every 30 minutes, pulling further staged scripts from GitHub (priujghtjytfcghffgt.txt, bhjfjkfgrtwehjbfgcf.txt) that self-delete after execution to minimize forensic residue. GitHub API polling doubles as a lightweight C2/beacon channel, using hardcoded personal access tokens and encoding host identity as <IP>-<MMDD_HHMM>-XXX-kkk.txt.
The final payload is one of several RC4-encrypted .NET AsyncRAT builds disguised as PNG image files (apple.png, fox.png, lion.png, rabbit.png, wolf.png) hosted in public GitHub repositories; a companion utility (rTom.exe_r) performs the RC4 decryption on the endpoint. Recovered C2 IPs are compiled directly into the AsyncRAT binaries, including a South Korea-hosted address (112.216.9[.]171); a link-local test address (169.254.33[.]137) surfaced in operator logs as an OPSEC failure.
Separately, Genians found the operator's own infrastructure running an experimental offline AI stack: Ollama (with generated SSH keys evidencing an actual local run, not just a download), GPT4All with a populated localdocs_v3.db confirming a working LocalDocs RAG configuration for querying stolen documents, and Msty as a second local-model front end. A NuGet package cache under Pictures\zzz\nupkg contained LLaMaSharp (with CUDA GPU backends), Microsoft.SemanticKernel, Microsoft.Agents.AI, LangChain.providers.llamasharp, and OpenAI/Azure.AI.OpenAI packages — indicating the operator is prototyping C#/.NET tooling that calls locally-hosted or commercial LLMs, consistent with public reporting that the underlying models are open-weight releases (e.g. Llama/Mistral/Gemma-class) run through Ollama rather than anything custom-trained. Whisper speech-to-text archives (faster-whisper.7z, whisper.7z) and a Korean-language guide on extracting text from audio point to planned use for transcribing intercepted calls/meetings. Cursor AI installers and edit history (including a file named Pumpfun-AI-Attack-Defence-Requirements.md) show the operator using an AI code editor in its own development workflow. AI-generated decoy PDFs on virtual-asset and investment themes carry python-docx/WPS 文字 authoring metadata and near-identical batch-generation timestamps (05:00 AM on 2026-03-11 and 2026-03-24), consistent with automated, templated lure production. Genians assesses this as a research/integration phase — assembling and testing existing open-source tooling rather than training or fielding a novel model — with no confirmed instance yet of the AI stack running live against a victim.
Attribution to Kimsuky/North Korea rests on multiple independent indicators: reuse of a publicly documented LNK-builder tool (lnkbuilder.exe) traceable to a September 2023 GitHub repository; an RTF/Gzip header-obfuscation technique matching a February 2024 Kimsuky campaign; PowerShell/Git-based C2 patterns consistent with the 2023 'FlowerPower' campaign; a non-existent 'Arirang' system-manufacturer string matching known North Korean device branding; Chinese-language WPS Office 2019 metadata; Dubeolsik-layout keystroke reconstruction showing North Korean spelling variants (e.g. 싸이트 vs. 사이트, 리력 vs. 이력) retained after backspace corrections; North Korean vocabulary in the operator's own search history (including virtual-asset reconnaissance queries); persistent Astrill VPN usage; and a GitHub account (brandonleeodd93-blip, registered to brandonleeodd.93@gmail.com) used to host the payload repositories. Fortinet independently corroborated attacks on South Korean targets from the same tooling family. The activity is consistent with Kimsuky's broader 2025-2026 trend of using generative AI for lure content, including a previously reported 2025 campaign using ChatGPT-generated South Korean military ID card images.
MITRE ATT&CK techniques used in TL-2026-2005
Discovery
T1007 System Service Discovery; T1010 Application Window Discovery; T1033 System Owner/User Discovery; T1057 Process Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information
Persistence
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol
Initial Access
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
Affected products and versions in Kimsuky 'Operation GitPower' Integrates Local AI Tooling
- Microsoft — Windows (LNK, PowerShell, and Task Scheduler execution surface)
Vulnerable versions: Not version-specific — abuses built-in LNK shell-link, PowerShell, and Task Scheduler functionality rather than a software vulnerability
Remediation for Kimsuky 'Operation GitPower' Integrates Local AI Tooling
Immediate actions
- Block egress to identified C2 IPs (112.216.9.171, 170.205.29.83, 170.205.30.227, 185.27.134.140, 27.102.137.126, 27.102.137.159, 27.102.138.44) and domain stoks.great-site.net
- Alert on outbound connections to the GitHub Raw Content/Contents API from non-developer endpoints, especially in diplomatic, defense, and virtual-asset business units
- Block or sandbox execution of .LNK files delivered inside ZIP email attachments at the mail gateway
- Hunt for the observed scheduled-task pattern (randomized all-caps 32-character task name, ~30-minute recurrence) and for PowerShell scripts written to %AppData% with random non-standard filenames
Workarounds
- Enable PowerShell Script Block Logging and AMSI to capture the obfuscated Base64/bitwise-decoded payload at runtime even when static detection misses it
- Restrict LNK execution from removable media, Downloads, and archive-extraction paths via GPO/AppLocker
Longer-term hardening
- Deploy EDR/behavioral detection tuned to LNK-spawned-PowerShell-to-scheduled-task chains rather than static content signatures, since AI-authored lures remove the translation/formatting tells defenders previously relied on
- Apply Attack Surface Reduction / AppLocker rules blocking PowerShell or cmd.exe as a child process of Explorer-launched LNK files from Downloads, Temp, or archive-extraction paths
- Inventory endpoints and servers for unauthorized local-LLM stacks (Ollama, GPT4All, Msty) as a novel compromise indicator, not just a policy violation
- Extend threat-hunting playbooks to cover GitHub-as-C2 patterns: personal-access-token abuse, periodic raw-content polling, and image-file-disguised payload staging in public repos
Timeline of Kimsuky 'Operation GitPower' Integrates Local AI Tooling
- The LNK-weaponization tool later reused as lnkbuilder.exe is published to a public GitHub repository, later linked to this campaign via tool reuse.
- A prior Kimsuky campaign disguised as a 'New Year Opinion Column' is publicly reported using the same RTF/Gzip header-obfuscation technique later observed in Operation GitPower payloads.
- Genians assesses Kimsuky began using AI-generated phishing decoy documents around the start of 2026.
- An AI-generated decoy PDF (virtual-asset/investment theme) is created with a python-docx/WPS 文字 authoring signature at 05:00:04 AM, consistent with automated batch generation.
- A second AI-generated decoy PDF batch is created at 05:00:44 AM, matching the same automated-generation signature as the March 11 batch.
- The Hacker News corroborates the Genians findings, citing Fortinet's independent observation of attacks against South Korean users using related tooling.
- Genians publishes 'Kimsuky Integrates AI into Attack Operations,' the original disclosure naming Operation GitPower, detailing the LNK-to-PowerShell/GitHub-C2/AsyncRAT chain and the operator's offline AI stack (Ollama, GPT4All LocalDocs, Msty, LLaMaSharp, Semantic Kernel, Cursor, Whisper).
- QuoIntelligence's Weekly Threat Intelligence Snapshot (Week 33 2026) flags the Operation GitPower AI-tooling campaign in its cyber-highlights roundup, prompting this hunt.
Sources cited for Kimsuky 'Operation GitPower' Integrates Local AI Tooling
- Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM
- Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
- Threat Intelligence Snapshot: Week 33 2026
- Kimsuky Uses Local LLMs, AI-Generated Lures and GitHub C2 to Deploy AsyncRAT
- North Korean Spy Group Kimsuky Built Offline AI Lab on Attack Servers to Analyze Stolen Files
- Report: North Korea's Kimsuky Turns AI Into a Crypto Hacking Weapon
- North Korean Hackers Explore AI Transcription for Stolen Calls and Meetings
Detection coverage for TL-2026-2005
As of 2026-08-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2005 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2005
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.