Kimsuky Uses AI-Generated Decoys and Experiments with Local LLMs

· Original article ↗

Summary

Genians’ analysis of Kimsuky-linked Operation GitPower details spear-phishing attacks using malicious LNK files, PowerShell and Git-based C2, and evidence the group is experimenting with local LLMs and AI development tools.

Key points

  • Genians tracks Operation GitPower as a continuation of Kimsuky activity, including tactics associated with the FlowerPower campaign.
  • Spear-phishing ZIP archives contain LNK files disguised as business documents; execution launches obfuscated PowerShell and can display a decoy PDF while malicious activity continues.
  • The attack establishes persistence with hidden scheduled tasks, collects system information and uses GitHub repositories for C2 and payload delivery.
  • Encrypted .NET AsyncRAT payloads were disguised as image files; a hardcoded GitHub access token identified in the analysis has been revoked.
  • Infrastructure logs showed Ollama, GPT4All and Msty installations, GPT4All RAG configuration, and AI development materials. The report found no evidence of independent AI model training.
  • Genians recommends correlating LNK execution, unusual PowerShell, scheduled tasks and Git service access through behavior-based detection and threat hunting.

Article Details

Attack Vectors
  • Spear-phishing emails and other distribution channels delivered ZIP archives containing malicious LNK files disguised as business documents.
  • Executing an LNK file decoded and launched an embedded PowerShell loader while displaying a PDF decoy.
  • PowerShell scripts downloaded additional files from GitHub repositories, established scheduled-task persistence, collected system information, and deployed encrypted AsyncRAT payloads disguised as images.
  • Documents assessed to have been created with generative AI were used as decoys; the report does not establish that the actor trained an AI model.
Defensive Notes
  • Correlate archive extraction and LNK execution with long shortcut arguments, custom Base64 decoding, hidden PowerShell processes, and scripts created in Temp or AppData.
  • Monitor hidden scheduled tasks, recurring GitHub Raw Content and Contents API access, and repository access using non-business accounts or personal access tokens.
  • Investigate encrypted .NET payloads with image extensions and correlate downloads with subsequent endpoint execution.
  • Prioritize behavior-based EDR detection over judgments based solely on decoy-document quality.

Indicators of compromise

TypeIndicatorContext
EMAILapollo1030109@gmail[.]comAddress listed in the report's email indicators.
EMAILawed33@outlook[.]krAddress listed in the report's email indicators.
EMAILbelendong40@gmail[.]comAddress listed in the report's email indicators.
EMAILbrandonleeodd[.]93@gmail[.]comAddress listed in the report's email indicators; also identified as a GitHub commit author's address in C2 testing logs.
EMAILcontrasde@outlook[.]krAddress listed in the report's email indicators.
EMAILdevlion413@gmail[.]comAddress listed in the report's email indicators.
EMAILeros1030109@gmail[.]comAddress listed in the report's email indicators.
EMAILhera1030109@gmail[.]comAddress listed in the report's email indicators.
EMAILholowin@gmail[.]comAddress listed in the report's email indicators.
EMAILholowin401@gmail[.]comAddress listed in the report's email indicators.
EMAILjecoma@outlook[.]krAddress listed in the report's email indicators.
EMAILjohnstones19850308@gmail[.]comAddress listed in the report's email indicators.
EMAILjohnstones8888@outlook[.]comAddress listed in the report's email indicators.
EMAILkkkkk79@outlook[.]krAddress listed in the report's email indicators.
EMAILtomas3015@outlook[.]krAddress listed in the report's email indicators.
EMAILtrungvo5131993@gmail[.]comAddress listed in the report's email indicators.
EMAILtttsssuuu@outlook[.]krAddress listed in the report's email indicators.
EMAILwhitewolf20000312@gmail[.]comAddress listed in the report's email indicators.
HOSTNAMEstoks[.]great-site[.]netHost listed in the report's domain indicators.
IPV4112[.]216[.]9[.]171AsyncRAT C2 address, also listed in the report's C2 indicators.
IPV4170[.]205[.]29[.]83Address listed in the report's C2 indicators.
IPV4170[.]205[.]30[.]227Address listed in the report's C2 indicators.
IPV4185[.]27[.]134[.]140Address listed in the report's C2 indicators.
IPV427[.]102[.]137[.]126Address listed in the report's C2 indicators.
IPV427[.]102[.]137[.]159Address listed in the report's C2 indicators.
IPV427[.]102[.]138[.]44Address listed in the report's C2 indicators.
MD502ebc2356f9f700bbdac444cdefa0da2Hash listed in the report's IoC section.
MD50d8ceb7dea7d471afa2f8e753b13d2d6Hash listed in the report's IoC section.
MD51f378c0efc13669dada1fe340c6837bdHash listed in the report's IoC section.
MD52669731cb5ff664dfb5fbfc37637876dHash listed in the report's IoC section.
MD52ab3df4762fbde5d86e99a1ad147850eHash listed in the report's IoC section.
MD52e76d5316663a3dc472398b1c01cb9a8Hash listed in the report's IoC section.
MD52eb77109cce1e8afca6245c2963e52a6Hash listed in the report's IoC section.
MD5302725413076d1aeaee2d7f2b3692646Hash listed in the report's IoC section.
MD530792a0c0dfad55fb2b19d3e30e9a7d4Hash listed in the report's IoC section.
MD530d5f17d5e3f85be18220a7cab0b9fffHash listed in the report's IoC section.
MD537cec428257cd41153cf43d7f1a12652Hash listed in the report's IoC section.
MD53b9d40f3d620ec87960b4350d42ccc03Hash listed in the report's IoC section.
MD53e2110d233d4543830e14c78d53900f4Hash listed in the report's IoC section.
MD5422a221851ea6ad15f53cd3aea51c8afHash listed in the report's IoC section.
MD549bdbe7e6cbb88842afcce3a9fe60e9bHash listed in the report's IoC section.
MD54d87fef16790cbe1df72007d99149665Hash listed in the report's IoC section.
MD55577fffb5b5acd3771ef9dc696498f1eHash listed in the report's IoC section.
MD55af95590a33b9bc64d95808f1fc71b78Hash listed in the report's IoC section.
MD55c5672bb14e1d2f07a8318ffec19b213Hash listed in the report's IoC section.
MD56add815cd61d6514f81a23ab8c23405aHash listed in the report's IoC section.
MD573ff669fc282653bd6c42cf87ade9337Hash listed in the report's IoC section.
MD57f12fa589f56f6203c692715b3958d30Hash listed in the report's IoC section.
MD58406075af0a1e9ec09bafdc0de01f138Hash listed in the report's IoC section.
MD58c859a03814443c6f0da341ee594c352Hash listed in the report's IoC section.
MD5a1c07ac866fb6b388e38c6bb1d4bbe94Hash listed in the report's IoC section.
MD5a343d8bcf02a0554fa271452a512f3ceHash listed in the report's IoC section.
MD5a435292106026e257789036a70ee1a14Hash listed in the report's IoC section.
MD5a5701848f82c65a55765dc534111899fHash listed in the report's IoC section.
MD5aa9d5dd632bb90addca480eaa5ff4382Hash listed in the report's IoC section.
MD5af3fa7f22f6e97901f20326cc12bdb49Hash listed in the report's IoC section.
MD5b406ea5b8628cb7801f47c0189b96182Hash listed in the report's IoC section.
MD5b50dad56d891ef230656b37ce62cdadaHash listed in the report's IoC section.
MD5b516ec6c6b37618ad65080a063270ea4Hash listed in the report's IoC section.
MD5ba0238423b5c29667cd760ccd7b000aaHash listed in the report's IoC section.
MD5ba8e682a72c6a3e634c070f0fb057bf5Hash listed in the report's IoC section.
MD5bbf1b0ab9fc27439de4386ed7b8fc151Hash listed in the report's IoC section.
MD5c410055bfa198937825dfd7e41000e7aHash listed in the report's IoC section.
MD5c63d021de798034cbf933e1c99bcb83fHash listed in the report's IoC section.
MD5c7723bf166ef08ff3112257a1244f584Hash listed in the report's IoC section.
MD5ca0b57807f79f26e7f59cab2a2542da0Hash listed in the report's IoC section.
MD5e0e4aec6d494fe68cdaa52d6878a8366Hash listed in the report's IoC section.
MD5e22367800e9d39bc865bd50cddd0537dHash listed in the report's IoC section.
MD5ead95793528572e7b89679860e2f2116Hash listed in the report's IoC section.
MD5ed2f8dd9b96d706d833b7aa545b8e621Hash listed in the report's IoC section.
MD5f4e7ca8c1de252840c1f0e957cd4b717Hash listed in the report's IoC section.
MD5f73e07efb8707e3561e9cbff74557acbHash listed in the report's IoC section.

MITRE ATT&CK

T1027 · Obfuscated Files or InformationLNK arguments concealed PowerShell with Base64 encoding, a custom decoder, long padding, and split URL strings.T1036.007 · Double File ExtensionA malicious shortcut was distributed with a filename ending in .pdf.lnk to resemble an investment document.T1053.005 · Scheduled TaskA hidden scheduled task ran an intermediate PowerShell script approximately five minutes after registration and then every 30 minutes.T1057 · Process DiscoveryThe information-collection script gathered a list of running processes.T1059.001 · PowerShellThe LNK launched PowerShell scripts that downloaded files, collected system information, and executed subsequent stages.T1071.001 · Web ProtocolsThe operation used GitHub repository access and API communications for command-and-control activity.T1082 · System Information DiscoveryA script collected operating-system, architecture, configuration, installation, and boot information from infected systems.T1105 · Ingress Tool TransferPowerShell downloaded additional scripts and payloads from GitHub repositories onto infected systems.T1140 · Deobfuscate/Decode Files or InformationThe LNK decoded an embedded PowerShell script; another described payload flow restored altered RTF-like headers to Gzip headers before decompression.T1204.002 · Malicious FileThe infection began when a user executed a malicious LNK file from the downloaded archive.T1566.001 · Spearphishing AttachmentSpear-phishing emails delivered ZIP archives containing malicious LNK attachments disguised as business documents.

People

Threat Actors

Malware

Vendors

Products

Tools

Countries

Industries

Related Articles