$ techbeacon▋
Darkweb

North Korean Kimsuky Deploys AI‑Driven Decoys and GitHub Tokens in New ‘GitPower’ Campaign

North Korean Kimsuky Deploys AI‑Driven Decoys and GitHub Tokens in New ‘GitPower’ Campaign

Cyber‑security researchers have identified a fresh wave of attacks attributed to the North Korean‑linked group known as Kimsuky, expanding its long‑running Operation GitPower. The latest intrusion set leverages malicious Windows shortcut files (LNK), GitHub personal access tokens (PATs) for payload delivery, and AI‑generated decoy documents that reference the OpenCode coding assistant.

According to the Genians Security Center, the threat actors distribute crafted LNK files through phishing emails and compromised web resources. When a victim clicks the shortcut, the file silently executes a script that contacts a GitHub repository using a stolen PAT. This token grants the attackers read and write privileges, allowing them to pull additional malware components directly from the repository without raising typical network‑traffic alarms.

The use of GitHub PATs marks a notable evolution in Kimsuky’s operational toolkit. By exploiting legitimate development platforms, the group can bypass many traditional security controls that flag suspicious file transfers or external command‑and‑control servers. Analysts say the approach also simplifies the logistics of updating malicious code, as developers can push new payloads to the same repository and have them automatically retrieved by infected hosts.

In tandem with the token‑based delivery, the campaign features AI‑crafted documents that masquerade as technical reports or project briefs. These files are generated by the OpenCode agent, an emerging AI coding assistant, and are embedded with benign‑looking text to entice recipients into opening them. Once opened, the documents trigger the same shortcut chain, further obscuring the attack’s origin. Security experts note that the inclusion of AI‑generated content adds a layer of credibility, making the decoys harder to distinguish from legitimate work‑related files.

While the precise targets of the latest GitPower operations have not been disclosed, Kimsuky historically focuses on government agencies, diplomatic entities, and organizations involved in policy research. The group’s long‑standing objective is to harvest credentials, conduct espionage, and exfiltrate sensitive information that can benefit Pyongyang’s strategic interests.

Genians advises organizations to tighten controls around the execution of LNK files, enforce strict token management policies on code‑hosting services, and employ heuristic detection for AI‑generated documents. As threat actors continue to blend legitimate development tools with malicious intent, security teams must adapt their defenses to recognize the subtle cues of such hybrid attacks.

Source: GBHackers
Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related