HomeSecurityNorth Korean hackers exploit LNKs and GitHub repositories

North Korean hackers exploit LNKs and GitHub repositories

North Korean (DPRK) hackers are choosing stealth over sophistication when targeting organizations in South Korea, as researchers report the use of weaponized Windows shortcut files (.LNK) and GitHub-based command and control (C2) channels in a new campaign. According to new findings from Fortinet, a series of attacks that began in 2024 were found to use a multi-stage process and GitHub C2 to evade detection, with stealth improving with each iteration of the campaign.

See also: Axios npm hack: North Korean hackers use fake Teams error

North Korean hackers
North Korean hackers exploit LNKs and GitHub repositories

The ongoing campaign appears to be aimed at expanding DPRK surveillance within South Korea. Researchers noted that less obfuscation and heavier metadata in previous iterations of the campaign allowed them to link it to attacks spreading the XenoRAT. Jason Soroko, a senior fellow at Sectigo, believes the strategy aligns with the recent trend of attackers relying on built-in Windows utilities and legitimate services to achieve their goals.

The campaign begins its infection with a Windows shortcut file, which is typically used to launch applications or open documents, but can also embed commands to execute scripts or binaries.

The LNK files in the campaign use various scripts, including previous versions with simple concatenation to mask the GitHub C2 address and access token, the researchers said, adding that it was easy to determine that the script was intended to execute a PowerShell command retrieved from GitHub.

See also: Google attributes Axios Supply Chain Attack to UNC1069

North Korean hackers exploit LNKs and GitHub repositories
North Korean hackers exploit LNKs and GitHub repositories

Later versions moved to basic character decoding features, making detection a bit more difficult, but still had prominent metadata like name, sizes, and modification dates that allowed researchers to link it to the specific campaign. The name column repeatedly uses “Hangul Document,” a pattern consistent with state-linked groups like Kimsuky, APT37 , and Lazarus.

In its latest iteration, the campaign operators have stripped out the identifying metadata, now using only a decryption function within the arguments. Researchers also highlighted the use of GitHub as a C2 layer in the campaign. Instead of communicating with suspicious or newly registered domains, the malware interacts with GitHub repositories and APIs to receive instructions and extract data.

After a system is infected, PowerShell scripts perform system checks to confirm that the environment is not under analysis, ensure that the malware persists after a system reboot via Scheduled Task, and collect detailed system information.

See also: Ghost Campaign: 7 malicious npm packages steal crypto wallets

North Korean hackers exploit LNKs and GitHub repositories

Only then is a stable connection attempted to subsequent scripts, where additional modules and instructions are retrieved from the attacker’s GitHub repository. The researchers point to a GitHub account, “motoralis,” with continuous activity since 2025, and other less frequent accounts, including “God0808RAMA,” “Pigresy80,” “entire73,” “pandora0009,” and “brandonleeodd93-blip.” Additionally, the blog post shared a set of URLs and hash functions to aid detection efforts.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS