Kimsuky-Linked Campaign Uses Malicious LNKs, GitHub PATs and AI-Generated Decoys

Summary
Genians analyzed 13 malicious LNKs linked to Kimsuky’s Operation GitPower, finding obfuscated PowerShell, GitHub PAT-based payload retrieval, hidden scheduled tasks, Pastebin fallback C2, anti-analysis checks, and decoys bearing opencode metadata.
Key points
- Genians examined 13 malicious LNK files collected between August 11 and 19, 2026. The files were disguised as business documents and delivered in ZIP archives, consistent with spearphishing.
- All samples launched PowerShell using lengthy, concealed command arguments and a custom decoder. Scripts retrieved decoys and follow-on payloads from GitHub Raw using hardcoded personal access tokens.
- The malware established persistence with hidden scheduled tasks disguised as legitimate software. Some variants also checked for analysis tools and sandbox usernames, deleted PowerShell command history, and stopped execution when analysis was detected.
- One variant used Pastebin to retrieve and execute a second-stage payload, providing an alternative to GitHub. Decoys included PDF, XLSX, and PNG files.
- Some PDF metadata named the AI coding agent opencode as the creator and producer. Across 29 collected decoy files, Genians identified 11 unique documents, with duplicates redistributed under randomized filenames; some included unreplaced placeholders.
- Genians assessed the activity as linked to Kimsuky’s Operation GitPower. It recommends correlating LNK execution, PowerShell activity, GitHub or Pastebin access, and scheduled-task creation for threat hunting and detection.
Article Details
- Attack Vectors
- Spearphishing distributes ZIP archives containing malicious LNK files disguised as business documents.
- The LNK files launch PowerShell with long, space-prefixed arguments that conceal an encrypted loader decoded at runtime.
- Second-stage scripts use hardcoded GitHub PATs to retrieve decoy documents and follow-on payloads from GitHub Raw Content. One variant also retrieves code from Pastebin and executes it in memory.
- Hidden scheduled tasks repeatedly run follow-on scripts. Some variants check for analysis tools or a sandbox username before continuing.
- Defensive Notes
- Correlate ZIP extraction and LNK execution with subsequent PowerShell processes, unusually long command lines, leading spaces, and newly created scripts in %AppData% or %TEMP%.
- Hunt for hidden scheduled tasks with names resembling BitLocker, MATLAB, or .NET tasks, especially when paired with recurring PowerShell execution.
- Investigate PowerShell access to GitHub Raw Content using PAT authorization headers and calls that retrieve and execute Pastebin content.
- Correlate analysis-tool process checks, PowerShell history deletion, script self-deletion, and recurring external communications in EDR telemetry.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
baras6600@proton[.]me | Email address listed in the article's IOC section. | |
choemiyang@hotmail[.]com | Email address listed in the article's IOC section. | |
dustinharrise91@outlook[.]com | Email address listed in the article's IOC section. | |
jackal3300@proton[.]me | Email address listed in the article's IOC section. | |
jametony8@outlook[.]com | Email address listed in the article's IOC section. | |
jamjack2026@proton[.]me | Email address listed in the article's IOC section. | |
montry111@proton[.]me | Email address listed in the article's IOC section. | |
sven5500@proton[.]me | Email address listed in the article's IOC section. | |
taini7700@outlook[.]com | Email address listed in the article's IOC section. | |
urusa4400@proton[.]me | Email address listed in the article's IOC section. | |
| MD5 | 10780939962b54addc9d31f57d80edfc | MD5 listed for a malicious LNK sample. |
| MD5 | 1523a2fcc901965ab4568d9fe829e4af | MD5 listed for a malicious LNK sample. |
| MD5 | 500e0bc0d7579fb338912770964076fe | MD5 listed for a malicious LNK sample. |
| MD5 | 685bfc6b2c29fbc16cfad908894add55 | MD5 listed for a malicious LNK sample. |
| MD5 | 7a53089053b1381742856a5cf2b95f8b | MD5 listed for a malicious LNK sample. |
| MD5 | 8db2f20b719dcb7029d6296505622093 | MD5 listed for a malicious LNK sample. |
| MD5 | 900e832c10d851bbdef3fb191a15db0e | MD5 listed for a malicious LNK sample. |
| MD5 | a2015665a3e18bf0ef86e3931245c7e6 | MD5 listed for a malicious LNK sample. |
| MD5 | bb88940e915b11f6330b7446f6037f5b | MD5 listed for a malicious LNK sample. |
| MD5 | ce5932b88f879f26006df81f2fa7667e | MD5 listed for a malicious LNK sample. |
| MD5 | d0894d4626aae0f96d6b84ca3bb71a36 | MD5 listed for a malicious LNK sample. |
| MD5 | e50f2ae7fb03675a1ef58b1cf9cda6d1 | MD5 listed for a malicious LNK sample. |
| MD5 | f648bdd3c2cd902e239149de86d43e8f | MD5 listed for a malicious LNK sample. |
| URL | hxxps[:]//pastebin[.]com/raw/gybpx38s | Specific Pastebin resource from which a persistence script retrieves code for in-memory execution. |
| URL | hxxps[:]//raw[.]githubusercontent[.]com/sven5500/firtfirter/main/ | GitHub Raw Content repository path used by a malicious loader to retrieve a decoy and follow-on payload. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationLNK arguments conceal an encrypted numeric-array payload; scripts also split URL strings and some LNK files contain extensive padding.T1036.005 · Match Legitimate Resource Name or LocationLNK files use document disguises and forged properties, while scheduled task names resemble legitimate software tasks.T1041 · Exfiltration Over C2 ChannelThe article's ATT&CK mapping reports upload of system information to GitHub over the C2 channel.T1053.005 · Scheduled TaskThe loaders register hidden scheduled tasks to execute follow-on scripts at recurring intervals.T1059.001 · PowerShellThe LNK files launch obfuscated PowerShell loaders and subsequent PowerShell scripts.T1070.003 · Clear Command HistoryA variant deletes the PSReadLine ConsoleHost_history.txt file when it detects an analysis environment.T1102 · Web ServiceThe attack retrieves commands or payloads through GitHub Raw Content and, in one variant, Pastebin.T1140 · Deobfuscate/Decode Files or InformationThe LNK loader decodes its numeric-array payload at runtime to restore a second-stage PowerShell script.T1202 · Indirect Command ExecutionA follow-on script launches PowerShell through conhost.exe --headless to avoid displaying a window.T1204.002 · Malicious FileInitial execution depends on a user opening a disguised LNK file extracted from a ZIP archive.T1497 · Virtualization/Sandbox EvasionOne variant checks for virtualization and analysis-tool processes and a presumed sandbox username, then terminates when detected.T1566.001 · Spearphishing AttachmentZIP archives distributed through spearphishing contain malicious LNK attachments.
Threat Actors
Vendors
GeniansGenians Security Center continues to track Git-based C2 attacks assessed to be carried out by Kimsuky, collectively known as Operation GitPower.GitHubDecoy documents and follow-on PowerShell commands retrieved from GitHub Raw Content paths using a GitHub PATPastebinSecond, Pastebin was observed being used as a second-stage payload delivery channel in addition to GitHub.
Products
Genian Insights EIntegrated Response Strategy Based on Genian Insights EGitHubDecoy documents and follow-on PowerShell commands retrieved from GitHub Raw Content paths using a GitHub PATPastebinSecond, Pastebin was observed being used as a second-stage payload delivery channel in addition to GitHub.PowerShellAll LNK files configured to launch PowerShell, with encrypted loaders concealed within lengthy execution arguments