Hackers, possibly linked to North Korea, are using GitHub as a command and control (C2) infrastructure in multi-stage attacks targeting organizations in South Korea. According to Fortinet FortiGuard Labs, the attack chain includes disguised Windows shortcut (LNK) files that act as a launching point for dropping a deceptive PDF document and a PowerShell script that sets the stage for the next phase of the attack.
See also: North Korean hackers exploit LNKs and GitHub repositories

It is believed that these LNK files are distributed via phishing emails. Once the payloads are downloaded, the victim views the PDF document, while the malicious PowerShell script runs silently in the background.
The PowerShell script performs checks to resist analysis by scanning for running processes related to virtual machines, debuggers, and forensic analysis tools. If such processes are detected, the script terminates immediately. Otherwise, it exports a Visual Basic Script (VBScript) and establishes persistence using a scheduled task that launches the PowerShell payload every 30 minutes in a hidden window to avoid detection.
This ensures that the PowerShell script is automatically executed after each system reboot. The PowerShell script then profiles the compromised computer, saves the result to a log file, and pushes it to a GitHub repository created under the account “motoralis” using a hardcoded access token. Some of the GitHub accounts created as part of the campaign include “God0808RAMA”, “Pigresy80”, “entire73”, “pandora0009”, and “brandonleeodd93-blip”.
The script then parses a specific file in the same GitHub repository to retrieve additional modules or instructions, thus allowing the operator to exploit the trust associated with a platform like GitHub to integrate and maintain continuous control over the infected computer.
See also: Axios npm hack: North Korean hackers use fake Teams error

Fortinet said that previous versions of the campaign relied on LNK files to spread malware families such as the Xeno RAT. It is worth noting that the use of GitHub C2 to distribute the Xeno RAT and its MoonPeak variant was documented by ENKI and Trellix last year. These attacks were attributed to a North Korean state-backed group known as Kimsuky.
“Instead of relying on complex custom malware, the malicious actor uses native Windows tools for deployment, evasion, and persistence,” said security researcher Cara Lin.
The revelation comes as AhnLab analyzed a similar LNK-based infection chain from Kimsuky that ultimately leads to the development of a Python-based backdoor.
The LNK files, as before, execute a PowerShell script and create a hidden folder at the path “C:\windirr” to prepare payloads, including a deceptive PDF and another LNK file that mimics a Hangul Word Processor (HWP). Intermediate payloads are also deployed to install persistence and launch a PowerShell script, which then uses Dropbox as a C2 channel to retrieve a batch script.
See also: Google attributes Axios Supply Chain Attack to UNC1069

The batch file downloads two separate ZIP files from a remote server (“quickcon[.]store”) and combines them to create a single file and extracts an XML task scheduler and a Python-based backdoor from it. The task scheduler is used to launch the implant. The Python-based malware supports the ability to download additional payloads and execute commands issued by the C2 server.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
