Kimsuky Uses AI-Generated Decoys and Experiments with Local LLMs

Summary
Genians’ analysis of Kimsuky-linked Operation GitPower details spear-phishing attacks using malicious LNK files, PowerShell and Git-based C2, and evidence the group is experimenting with local LLMs and AI development tools.
Key points
- Genians tracks Operation GitPower as a continuation of Kimsuky activity, including tactics associated with the FlowerPower campaign.
- Spear-phishing ZIP archives contain LNK files disguised as business documents; execution launches obfuscated PowerShell and can display a decoy PDF while malicious activity continues.
- The attack establishes persistence with hidden scheduled tasks, collects system information and uses GitHub repositories for C2 and payload delivery.
- Encrypted .NET AsyncRAT payloads were disguised as image files; a hardcoded GitHub access token identified in the analysis has been revoked.
- Infrastructure logs showed Ollama, GPT4All and Msty installations, GPT4All RAG configuration, and AI development materials. The report found no evidence of independent AI model training.
- Genians recommends correlating LNK execution, unusual PowerShell, scheduled tasks and Git service access through behavior-based detection and threat hunting.
Article Details
- Attack Vectors
- Spear-phishing emails and other distribution channels delivered ZIP archives containing malicious LNK files disguised as business documents.
- Executing an LNK file decoded and launched an embedded PowerShell loader while displaying a PDF decoy.
- PowerShell scripts downloaded additional files from GitHub repositories, established scheduled-task persistence, collected system information, and deployed encrypted AsyncRAT payloads disguised as images.
- Documents assessed to have been created with generative AI were used as decoys; the report does not establish that the actor trained an AI model.
- Defensive Notes
- Correlate archive extraction and LNK execution with long shortcut arguments, custom Base64 decoding, hidden PowerShell processes, and scripts created in Temp or AppData.
- Monitor hidden scheduled tasks, recurring GitHub Raw Content and Contents API access, and repository access using non-business accounts or personal access tokens.
- Investigate encrypted .NET payloads with image extensions and correlate downloads with subsequent endpoint execution.
- Prioritize behavior-based EDR detection over judgments based solely on decoy-document quality.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
apollo1030109@gmail[.]com | Address listed in the report's email indicators. | |
awed33@outlook[.]kr | Address listed in the report's email indicators. | |
belendong40@gmail[.]com | Address listed in the report's email indicators. | |
brandonleeodd[.]93@gmail[.]com | Address listed in the report's email indicators; also identified as a GitHub commit author's address in C2 testing logs. | |
contrasde@outlook[.]kr | Address listed in the report's email indicators. | |
devlion413@gmail[.]com | Address listed in the report's email indicators. | |
eros1030109@gmail[.]com | Address listed in the report's email indicators. | |
hera1030109@gmail[.]com | Address listed in the report's email indicators. | |
holowin@gmail[.]com | Address listed in the report's email indicators. | |
holowin401@gmail[.]com | Address listed in the report's email indicators. | |
jecoma@outlook[.]kr | Address listed in the report's email indicators. | |
johnstones19850308@gmail[.]com | Address listed in the report's email indicators. | |
johnstones8888@outlook[.]com | Address listed in the report's email indicators. | |
kkkkk79@outlook[.]kr | Address listed in the report's email indicators. | |
tomas3015@outlook[.]kr | Address listed in the report's email indicators. | |
trungvo5131993@gmail[.]com | Address listed in the report's email indicators. | |
tttsssuuu@outlook[.]kr | Address listed in the report's email indicators. | |
whitewolf20000312@gmail[.]com | Address listed in the report's email indicators. | |
| HOSTNAME | stoks[.]great-site[.]net | Host listed in the report's domain indicators. |
| IPV4 | 112[.]216[.]9[.]171 | AsyncRAT C2 address, also listed in the report's C2 indicators. |
| IPV4 | 170[.]205[.]29[.]83 | Address listed in the report's C2 indicators. |
| IPV4 | 170[.]205[.]30[.]227 | Address listed in the report's C2 indicators. |
| IPV4 | 185[.]27[.]134[.]140 | Address listed in the report's C2 indicators. |
| IPV4 | 27[.]102[.]137[.]126 | Address listed in the report's C2 indicators. |
| IPV4 | 27[.]102[.]137[.]159 | Address listed in the report's C2 indicators. |
| IPV4 | 27[.]102[.]138[.]44 | Address listed in the report's C2 indicators. |
| MD5 | 02ebc2356f9f700bbdac444cdefa0da2 | Hash listed in the report's IoC section. |
| MD5 | 0d8ceb7dea7d471afa2f8e753b13d2d6 | Hash listed in the report's IoC section. |
| MD5 | 1f378c0efc13669dada1fe340c6837bd | Hash listed in the report's IoC section. |
| MD5 | 2669731cb5ff664dfb5fbfc37637876d | Hash listed in the report's IoC section. |
| MD5 | 2ab3df4762fbde5d86e99a1ad147850e | Hash listed in the report's IoC section. |
| MD5 | 2e76d5316663a3dc472398b1c01cb9a8 | Hash listed in the report's IoC section. |
| MD5 | 2eb77109cce1e8afca6245c2963e52a6 | Hash listed in the report's IoC section. |
| MD5 | 302725413076d1aeaee2d7f2b3692646 | Hash listed in the report's IoC section. |
| MD5 | 30792a0c0dfad55fb2b19d3e30e9a7d4 | Hash listed in the report's IoC section. |
| MD5 | 30d5f17d5e3f85be18220a7cab0b9fff | Hash listed in the report's IoC section. |
| MD5 | 37cec428257cd41153cf43d7f1a12652 | Hash listed in the report's IoC section. |
| MD5 | 3b9d40f3d620ec87960b4350d42ccc03 | Hash listed in the report's IoC section. |
| MD5 | 3e2110d233d4543830e14c78d53900f4 | Hash listed in the report's IoC section. |
| MD5 | 422a221851ea6ad15f53cd3aea51c8af | Hash listed in the report's IoC section. |
| MD5 | 49bdbe7e6cbb88842afcce3a9fe60e9b | Hash listed in the report's IoC section. |
| MD5 | 4d87fef16790cbe1df72007d99149665 | Hash listed in the report's IoC section. |
| MD5 | 5577fffb5b5acd3771ef9dc696498f1e | Hash listed in the report's IoC section. |
| MD5 | 5af95590a33b9bc64d95808f1fc71b78 | Hash listed in the report's IoC section. |
| MD5 | 5c5672bb14e1d2f07a8318ffec19b213 | Hash listed in the report's IoC section. |
| MD5 | 6add815cd61d6514f81a23ab8c23405a | Hash listed in the report's IoC section. |
| MD5 | 73ff669fc282653bd6c42cf87ade9337 | Hash listed in the report's IoC section. |
| MD5 | 7f12fa589f56f6203c692715b3958d30 | Hash listed in the report's IoC section. |
| MD5 | 8406075af0a1e9ec09bafdc0de01f138 | Hash listed in the report's IoC section. |
| MD5 | 8c859a03814443c6f0da341ee594c352 | Hash listed in the report's IoC section. |
| MD5 | a1c07ac866fb6b388e38c6bb1d4bbe94 | Hash listed in the report's IoC section. |
| MD5 | a343d8bcf02a0554fa271452a512f3ce | Hash listed in the report's IoC section. |
| MD5 | a435292106026e257789036a70ee1a14 | Hash listed in the report's IoC section. |
| MD5 | a5701848f82c65a55765dc534111899f | Hash listed in the report's IoC section. |
| MD5 | aa9d5dd632bb90addca480eaa5ff4382 | Hash listed in the report's IoC section. |
| MD5 | af3fa7f22f6e97901f20326cc12bdb49 | Hash listed in the report's IoC section. |
| MD5 | b406ea5b8628cb7801f47c0189b96182 | Hash listed in the report's IoC section. |
| MD5 | b50dad56d891ef230656b37ce62cdada | Hash listed in the report's IoC section. |
| MD5 | b516ec6c6b37618ad65080a063270ea4 | Hash listed in the report's IoC section. |
| MD5 | ba0238423b5c29667cd760ccd7b000aa | Hash listed in the report's IoC section. |
| MD5 | ba8e682a72c6a3e634c070f0fb057bf5 | Hash listed in the report's IoC section. |
| MD5 | bbf1b0ab9fc27439de4386ed7b8fc151 | Hash listed in the report's IoC section. |
| MD5 | c410055bfa198937825dfd7e41000e7a | Hash listed in the report's IoC section. |
| MD5 | c63d021de798034cbf933e1c99bcb83f | Hash listed in the report's IoC section. |
| MD5 | c7723bf166ef08ff3112257a1244f584 | Hash listed in the report's IoC section. |
| MD5 | ca0b57807f79f26e7f59cab2a2542da0 | Hash listed in the report's IoC section. |
| MD5 | e0e4aec6d494fe68cdaa52d6878a8366 | Hash listed in the report's IoC section. |
| MD5 | e22367800e9d39bc865bd50cddd0537d | Hash listed in the report's IoC section. |
| MD5 | ead95793528572e7b89679860e2f2116 | Hash listed in the report's IoC section. |
| MD5 | ed2f8dd9b96d706d833b7aa545b8e621 | Hash listed in the report's IoC section. |
| MD5 | f4e7ca8c1de252840c1f0e957cd4b717 | Hash listed in the report's IoC section. |
| MD5 | f73e07efb8707e3561e9cbff74557acb | Hash listed in the report's IoC section. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationLNK arguments concealed PowerShell with Base64 encoding, a custom decoder, long padding, and split URL strings.T1036.007 · Double File ExtensionA malicious shortcut was distributed with a filename ending in .pdf.lnk to resemble an investment document.T1053.005 · Scheduled TaskA hidden scheduled task ran an intermediate PowerShell script approximately five minutes after registration and then every 30 minutes.T1057 · Process DiscoveryThe information-collection script gathered a list of running processes.T1059.001 · PowerShellThe LNK launched PowerShell scripts that downloaded files, collected system information, and executed subsequent stages.T1071.001 · Web ProtocolsThe operation used GitHub repository access and API communications for command-and-control activity.T1082 · System Information DiscoveryA script collected operating-system, architecture, configuration, installation, and boot information from infected systems.T1105 · Ingress Tool TransferPowerShell downloaded additional scripts and payloads from GitHub repositories onto infected systems.T1140 · Deobfuscate/Decode Files or InformationThe LNK decoded an embedded PowerShell script; another described payload flow restored altered RTF-like headers to Gzip headers before decompression.T1204.002 · Malicious FileThe infection began when a user executed a malicious LNK file from the downloaded archive.T1566.001 · Spearphishing AttachmentSpear-phishing emails delivered ZIP archives containing malicious LNK attachments disguised as business documents.
People
Threat Actors
APT37Separately cited for its previously disclosed use of an internally developed LNK creation tool in attacks; the report does not identify it as the operator of the activity analyzed here.KimsukyGroup to which the report assesses the tracked Git-based attacks and AI-related infrastructure activity are associated.
Malware
Vendors
Products
Genian Insights EIntegrated Response Strategy Based on "Genian Insights E"GitHubHighlighted the need to strengthen behavior-based EDR detection and threat hunting against the abuse of LNK files, PowerShell, and GitHub.GitLabGenians Security Center has been continuously tracking GitHub- and GitLab-based attack activity assessed to be associated with Kimsuky, a cyber threat group known to operate under North Korea's Reconnaissance GeneralMicrosoft DefenderIn its operating environment, the threat actor wrote a question in Korean asking how to disable the Report feature in Microsoft Defender and then translated it into English using Google Translate.WPS Office 2019The threat actor was found to have opened the "Marketing-Service-Agreement-Pumpfun-AI-Attack-Defence.docx" document using the Chinese-language version of WPS Office 2019.
Tools
Cursor AIEvidence of Cursor AI Use in Kimsuky InfrastructureGPT4AllObserved indications that the Kimsuky group built and operated local LLM environments using Ollama, GPT4All, and Msty.LNK File BuilderAnalysis confirmed that the file matched the CLI-based LNK File Builder distributed through a GitHub repository published in September 2023.MstyObserved indications that the Kimsuky group built and operated local LLM environments using Ollama, GPT4All, and Msty.OllamaObserved indications that the Kimsuky group built and operated local LLM environments using Ollama, GPT4All, and Msty.
Countries
Industries
AcademiaFor many years, the Kimsuky group has conducted various spear phishing attacks targeting professionals and organizations in the fields of policy, academia, international cooperation, diplomacy, and security research.Financial ServicesGovernmentMilitaryContinued targeted attacks against foreign diplomatic missions, as well as the military, security, and virtual asset sectors.Security researchFor many years, the Kimsuky group has conducted various spear phishing attacks targeting professionals and organizations in the fields of policy, academia, international cooperation, diplomacy, and security research.Virtual assetsCases have also been identified in which documents related to virtual assets and finance, assessed to have been created using generative AI, were used as attack lures.