# Kimsuky 'Operation GitPower' Integrates Local AI Tooling into AsyncRAT Espionage Campaign

> North Korean state-sponsored actor Kimsuky is running Operation GitPower, a spear-phishing campaign against diplomatic missions, military/security organizations, policy and academic communities, and the virtual-asset sector, using an LNK-to-PowerShell infection chain and GitHub-hosted repositories as a C2 channel to deliver RC4-encrypted .NET AsyncRAT payloads disguised as image files. Genians (original discloser) found the same servers running an offline local-LLM stack (Ollama, GPT4All with a configured LocalDocs RAG database, Msty) plus AI development tooling (Cursor, LLaMaSharp, Microsoft Semantic Kernel, Whisper) that the operator is using to author AI-generated decoy documents and prototype document-analysis/automation workflows against stolen material.

- **Published:** 2026-08-13T00:00:00Z
- **Last reviewed:** 2026-08-13T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2005
- **ID:** TL-2026-2005
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** Kimsuky (North Korea)
- **Detections:** 9 · **IOCs:** 27 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Genians (2026-08-10) documents Operation GitPower as a continuation of long-running Kimsuky spear-phishing activity rather than a new campaign. Victims receive ZIP archives containing a malicious LNK disguised as a business document (honorarium requests, embassy correspondence, investment strategy packs). The LNK carries an ~3,800-character embedded PowerShell command padded with roughly 300 consecutive spaces and false shortcut metadata to hide its content from casual inspection, and decodes its payload with a custom bitwise Base64 routine rather than a standard cmdlet. The first-stage script fetches a decoy PDF from the GitHub Raw Content API (URL assembled via string concatenation to evade static string matching), displays it to the victim, and in the background writes an intermediate script to %AppData%\irujkdnjhgttrhdkfdu.ps1. Persistence is established via a hidden Scheduled Task with a randomized all-caps name (e.g. ZHUYHJGTYTFSUHIPOKLKHJHUYGVHGNFH) that fires ~5 minutes after registration and then every 30 minutes, pulling further staged scripts from GitHub (priujghtjytfcghffgt.txt, bhjfjkfgrtwehjbfgcf.txt) that self-delete after execution to minimize forensic residue. GitHub API polling doubles as a lightweight C2/beacon channel, using hardcoded personal access tokens and encoding host identity as <IP>-<MMDD_HHMM>-XXX-kkk.txt.

The final payload is one of several RC4-encrypted .NET AsyncRAT builds disguised as PNG image files (apple.png, fox.png, lion.png, rabbit.png, wolf.png) hosted in public GitHub repositories; a companion utility (rTom.exe_r) performs the RC4 decryption on the endpoint. Recovered C2 IPs are compiled directly into the AsyncRAT binaries, including a South Korea-hosted address (112.216.9[.]171); a link-local test address (169.254.33[.]137) surfaced in operator logs as an OPSEC failure.

Separately, Genians found the operator's own infrastructure running an experimental offline AI stack: Ollama (with generated SSH keys evidencing an actual local run, not just a download), GPT4All with a populated localdocs_v3.db confirming a working LocalDocs RAG configuration for querying stolen documents, and Msty as a second local-model front end. A NuGet package cache under Pictures\zzz\nupkg contained LLaMaSharp (with CUDA GPU backends), Microsoft.SemanticKernel, Microsoft.Agents.AI, LangChain.providers.llamasharp, and OpenAI/Azure.AI.OpenAI packages — indicating the operator is prototyping C#/.NET tooling that calls locally-hosted or commercial LLMs, consistent with public reporting that the underlying models are open-weight releases (e.g. Llama/Mistral/Gemma-class) run through Ollama rather than anything custom-trained. Whisper speech-to-text archives (faster-whisper.7z, whisper.7z) and a Korean-language guide on extracting text from audio point to planned use for transcribing intercepted calls/meetings. Cursor AI installers and edit history (including a file named Pumpfun-AI-Attack-Defence-Requirements.md) show the operator using an AI code editor in its own development workflow. AI-generated decoy PDFs on virtual-asset and investment themes carry python-docx/WPS 文字 authoring metadata and near-identical batch-generation timestamps (05:00 AM on 2026-03-11 and 2026-03-24), consistent with automated, templated lure production. Genians assesses this as a research/integration phase — assembling and testing existing open-source tooling rather than training or fielding a novel model — with no confirmed instance yet of the AI stack running live against a victim.

Attribution to Kimsuky/North Korea rests on multiple independent indicators: reuse of a publicly documented LNK-builder tool (lnkbuilder.exe) traceable to a September 2023 GitHub repository; an RTF/Gzip header-obfuscation technique matching a February 2024 Kimsuky campaign; PowerShell/Git-based C2 patterns consistent with the 2023 'FlowerPower' campaign; a non-existent 'Arirang' system-manufacturer string matching known North Korean device branding; Chinese-language WPS Office 2019 metadata; Dubeolsik-layout keystroke reconstruction showing North Korean spelling variants (e.g. 싸이트 vs. 사이트, 리력 vs. 이력) retained after backspace corrections; North Korean vocabulary in the operator's own search history (including virtual-asset reconnaissance queries); persistent Astrill VPN usage; and a GitHub account (brandonleeodd93-blip, registered to brandonleeodd.93@gmail.com) used to host the payload repositories. Fortinet independently corroborated attacks on South Korean targets from the same tooling family. The activity is consistent with Kimsuky's broader 2025-2026 trend of using generative AI for lure content, including a previously reported 2025 campaign using ChatGPT-generated South Korean military ID card images.

## MITRE ATT&CK

- T1566 Phishing
- T1059 Command and Scripting Interpreter
- T1053 Scheduled Task/Job
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1007 System Service Discovery
- T1010 Application Window Discovery
- T1057 Process Discovery
- T1033 System Owner/User Discovery
- T1071 Application Layer Protocol
- T1567 Exfiltration Over Web Service
- T1588 Obtain Capabilities
- T1585 Establish Accounts

## Sources

- [Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM](https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm)
- [Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development](https://thehackernews.com/2026/08/kimsuky-builds-offline-ai-stack-that.html)
- [Threat Intelligence Snapshot: Week 33 2026](https://quointelligence.eu/2026/08/threat-intelligence-snapshot-week-33-2026/)
- [Kimsuky Uses Local LLMs, AI-Generated Lures and GitHub C2 to Deploy AsyncRAT](https://cybersecuritynews.com/kimsuky-uses-local-llms/)
- [North Korean Spy Group Kimsuky Built Offline AI Lab on Attack Servers to Analyze Stolen Files](https://www.techtimes.com/articles/323690/20260810/north-korean-spy-group-kimsuky-built-offline-ai-lab-attack-servers-analyze-stolen-files.htm)
- [Report: North Korea's Kimsuky Turns AI Into a Crypto Hacking Weapon](https://news.bitcoin.com/security/report-north-koreas-kimsuky-turns-ai-into-a-crypto-hacking-weapon/)
- [North Korean Hackers Explore AI Transcription for Stolen Calls and Meetings](https://gbhackers.com/north-korean-explore-ai-transcription/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2005
