Kimsuky-Linked Campaign Uses Malicious LNKs, GitHub PATs and AI-Generated Decoys

· Original article ↗

Summary

Genians analyzed 13 malicious LNKs linked to Kimsuky’s Operation GitPower, finding obfuscated PowerShell, GitHub PAT-based payload retrieval, hidden scheduled tasks, Pastebin fallback C2, anti-analysis checks, and decoys bearing opencode metadata.

Key points

  • Genians examined 13 malicious LNK files collected between August 11 and 19, 2026. The files were disguised as business documents and delivered in ZIP archives, consistent with spearphishing.
  • All samples launched PowerShell using lengthy, concealed command arguments and a custom decoder. Scripts retrieved decoys and follow-on payloads from GitHub Raw using hardcoded personal access tokens.
  • The malware established persistence with hidden scheduled tasks disguised as legitimate software. Some variants also checked for analysis tools and sandbox usernames, deleted PowerShell command history, and stopped execution when analysis was detected.
  • One variant used Pastebin to retrieve and execute a second-stage payload, providing an alternative to GitHub. Decoys included PDF, XLSX, and PNG files.
  • Some PDF metadata named the AI coding agent opencode as the creator and producer. Across 29 collected decoy files, Genians identified 11 unique documents, with duplicates redistributed under randomized filenames; some included unreplaced placeholders.
  • Genians assessed the activity as linked to Kimsuky’s Operation GitPower. It recommends correlating LNK execution, PowerShell activity, GitHub or Pastebin access, and scheduled-task creation for threat hunting and detection.

Article Details

Attack Vectors
  • Spearphishing distributes ZIP archives containing malicious LNK files disguised as business documents.
  • The LNK files launch PowerShell with long, space-prefixed arguments that conceal an encrypted loader decoded at runtime.
  • Second-stage scripts use hardcoded GitHub PATs to retrieve decoy documents and follow-on payloads from GitHub Raw Content. One variant also retrieves code from Pastebin and executes it in memory.
  • Hidden scheduled tasks repeatedly run follow-on scripts. Some variants check for analysis tools or a sandbox username before continuing.
Defensive Notes
  • Correlate ZIP extraction and LNK execution with subsequent PowerShell processes, unusually long command lines, leading spaces, and newly created scripts in %AppData% or %TEMP%.
  • Hunt for hidden scheduled tasks with names resembling BitLocker, MATLAB, or .NET tasks, especially when paired with recurring PowerShell execution.
  • Investigate PowerShell access to GitHub Raw Content using PAT authorization headers and calls that retrieve and execute Pastebin content.
  • Correlate analysis-tool process checks, PowerShell history deletion, script self-deletion, and recurring external communications in EDR telemetry.

Indicators of compromise

TypeIndicatorContext
EMAILbaras6600@proton[.]meEmail address listed in the article's IOC section.
EMAILchoemiyang@hotmail[.]comEmail address listed in the article's IOC section.
EMAILdustinharrise91@outlook[.]comEmail address listed in the article's IOC section.
EMAILjackal3300@proton[.]meEmail address listed in the article's IOC section.
EMAILjametony8@outlook[.]comEmail address listed in the article's IOC section.
EMAILjamjack2026@proton[.]meEmail address listed in the article's IOC section.
EMAILmontry111@proton[.]meEmail address listed in the article's IOC section.
EMAILsven5500@proton[.]meEmail address listed in the article's IOC section.
EMAILtaini7700@outlook[.]comEmail address listed in the article's IOC section.
EMAILurusa4400@proton[.]meEmail address listed in the article's IOC section.
MD510780939962b54addc9d31f57d80edfcMD5 listed for a malicious LNK sample.
MD51523a2fcc901965ab4568d9fe829e4afMD5 listed for a malicious LNK sample.
MD5500e0bc0d7579fb338912770964076feMD5 listed for a malicious LNK sample.
MD5685bfc6b2c29fbc16cfad908894add55MD5 listed for a malicious LNK sample.
MD57a53089053b1381742856a5cf2b95f8bMD5 listed for a malicious LNK sample.
MD58db2f20b719dcb7029d6296505622093MD5 listed for a malicious LNK sample.
MD5900e832c10d851bbdef3fb191a15db0eMD5 listed for a malicious LNK sample.
MD5a2015665a3e18bf0ef86e3931245c7e6MD5 listed for a malicious LNK sample.
MD5bb88940e915b11f6330b7446f6037f5bMD5 listed for a malicious LNK sample.
MD5ce5932b88f879f26006df81f2fa7667eMD5 listed for a malicious LNK sample.
MD5d0894d4626aae0f96d6b84ca3bb71a36MD5 listed for a malicious LNK sample.
MD5e50f2ae7fb03675a1ef58b1cf9cda6d1MD5 listed for a malicious LNK sample.
MD5f648bdd3c2cd902e239149de86d43e8fMD5 listed for a malicious LNK sample.
URLhxxps[:]//pastebin[.]com/raw/gybpx38sSpecific Pastebin resource from which a persistence script retrieves code for in-memory execution.
URLhxxps[:]//raw[.]githubusercontent[.]com/sven5500/firtfirter/main/GitHub Raw Content repository path used by a malicious loader to retrieve a decoy and follow-on payload.

MITRE ATT&CK

T1027 · Obfuscated Files or InformationLNK arguments conceal an encrypted numeric-array payload; scripts also split URL strings and some LNK files contain extensive padding.T1036.005 · Match Legitimate Resource Name or LocationLNK files use document disguises and forged properties, while scheduled task names resemble legitimate software tasks.T1041 · Exfiltration Over C2 ChannelThe article's ATT&CK mapping reports upload of system information to GitHub over the C2 channel.T1053.005 · Scheduled TaskThe loaders register hidden scheduled tasks to execute follow-on scripts at recurring intervals.T1059.001 · PowerShellThe LNK files launch obfuscated PowerShell loaders and subsequent PowerShell scripts.T1070.003 · Clear Command HistoryA variant deletes the PSReadLine ConsoleHost_history.txt file when it detects an analysis environment.T1102 · Web ServiceThe attack retrieves commands or payloads through GitHub Raw Content and, in one variant, Pastebin.T1140 · Deobfuscate/Decode Files or InformationThe LNK loader decodes its numeric-array payload at runtime to restore a second-stage PowerShell script.T1202 · Indirect Command ExecutionA follow-on script launches PowerShell through conhost.exe --headless to avoid displaying a window.T1204.002 · Malicious FileInitial execution depends on a user opening a disguised LNK file extracted from a ZIP archive.T1497 · Virtualization/Sandbox EvasionOne variant checks for virtualization and analysis-tool processes and a presumed sandbox username, then terminates when detected.T1566.001 · Spearphishing AttachmentZIP archives distributed through spearphishing contain malicious LNK attachments.

Threat Actors

Vendors

Products

Tools

Countries

Industries

Related Articles