HomeSecurityNorth Korean hackers use GitHub as C2 in attacks

North Korean hackers use GitHub as C2 in attacks

Hackers, possibly linked to North Korea, are using GitHub as a command and control (C2) infrastructure in multi-stage attacks targeting organizations in South Korea. According to Fortinet FortiGuard Labs, the attack chain includes disguised Windows shortcut (LNK) files that act as a launching point for dropping a deceptive PDF document and a PowerShell script that sets the stage for the next phase of the attack.

See also: North Korean hackers exploit LNKs and GitHub repositories

GitHub

It is believed that these LNK files are distributed via phishing emails. Once the payloads are downloaded, the victim views the PDF document, while the malicious PowerShell script runs silently in the background.

The PowerShell script performs checks to resist analysis by scanning for running processes related to virtual machines, debuggers, and forensic analysis tools. If such processes are detected, the script terminates immediately. Otherwise, it exports a Visual Basic Script (VBScript) and establishes persistence using a scheduled task that launches the PowerShell payload every 30 minutes in a hidden window to avoid detection.

This ensures that the PowerShell script is automatically executed after each system reboot. The PowerShell script then profiles the compromised computer, saves the result to a log file, and pushes it to a GitHub repository created under the account “motoralis” using a hardcoded access token. Some of the GitHub accounts created as part of the campaign include “God0808RAMA”, “Pigresy80”, “entire73”, “pandora0009”, and “brandonleeodd93-blip”.

The script then parses a specific file in the same GitHub repository to retrieve additional modules or instructions, thus allowing the operator to exploit the trust associated with a platform like GitHub to integrate and maintain continuous control over the infected computer.

See also: Axios npm hack: North Korean hackers use fake Teams error

North Korean hackers use GitHub as C2 in attacks

Fortinet said that previous versions of the campaign relied on LNK files to spread malware families such as the Xeno RAT. It is worth noting that the use of GitHub C2 to distribute the Xeno RAT and its MoonPeak variant was documented by ENKI and Trellix last year. These attacks were attributed to a North Korean state-backed group known as Kimsuky.

“Instead of relying on complex custom malware, the malicious actor uses native Windows tools for deployment, evasion, and persistence,” said security researcher Cara Lin.

The revelation comes as AhnLab analyzed a similar LNK-based infection chain from Kimsuky that ultimately leads to the development of a Python-based backdoor.

The LNK files, as before, execute a PowerShell script and create a hidden folder at the path “C:\windirr” to prepare payloads, including a deceptive PDF and another LNK file that mimics a Hangul Word Processor (HWP). Intermediate payloads are also deployed to install persistence and launch a PowerShell script, which then uses Dropbox as a C2 channel to retrieve a batch script.

See also: Google attributes Axios Supply Chain Attack to UNC1069

North Korean hackers-UN officials

The batch file downloads two separate ZIP files from a remote server (“quickcon[.]store”) and combines them to create a single file and extracts an XML task scheduler and a Python-based backdoor from it. The task scheduler is used to launch the implant. The Python-based malware supports the ability to download additional payloads and execute commands issued by the C2 server.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS