The North Korean-backed APT group Kimsuky has stepped up its cyber operations, using GitHub repositories to distribute malware and extract data, marking an evolution in their attack methodology
See also: GPUGate malware: Exploiting GitHub and Google Ads for attacks

This latest campaign demonstrates the Kimsuky group's growing expertise in exploiting legitimate cloud infrastructure to evade traditional security measures while maintaining continued access to compromised systems.
The attack chain begins with a malicious ZIP archive containing a LNK file disguised as an electronic invoice. When executed, this malicious shortcut launches a PowerShell command that downloads and executes additional malicious scripts from GitHub repositories controlled by the attackers.
The initial payload creates a base for systematic data collection and maintains long-term persistence on infected systems. S2W researchers identified nine private GitHub repositories associated with this campaign, including group_0717, group_0721, test, hometax , and group_0803.
Kimsuky embedded hardcoded GitHub Private Tokens directly into their PowerShell scripts to access these repositories, demonstrating careful enterprise security design. Analysis of commit history revealed the attacker's email address (sahiwalsuzuki4[@]gmail.com) used when creating the GitHub account.
See also: GhostAction campaign steals 3325 secrets in GitHub attack

The malware’s persistence mechanism represents a particularly sophisticated approach to maintaining long-term access. Upon initial infection, the main.ps1 script creates a file named MicrosoftEdgeUpdate.ps1 in the %AppData% directory and creates a scheduled task named “ BitLocker MDM policy Refresh{DBHDFE12-496SDF-Q48D-SDEF-1865BCAD7E00} ”. This task runs every 30 minutes after an initial 5-minute delay, creating an automated system to retrieve and execute updated PowerShell scripts from the GitHub repository .
The malware uses a dynamic script management system that timestamps infected systems and creates custom folders for data extraction. The PowerShell payload downloads a file named real.txt from the repository, replaces placeholder strings with timestamped values (ntxBill_{MMdd_HHmm}), and reloads the modified script using a time-specific filename format. This mechanism allows attackers to track individual infections and manage multiple compromised systems simultaneously.
See also: Salesloft Drift attack linked to GitHub breach

The information theft component collects comprehensive system metadata, including IP addresses, boot times, operating system details, hardware specifications, device types, installation dates, and running processes. All collected data is compiled into log files and uploaded to the attacker's repository under time-stamped folders, creating an organized database of threat actor information.
