Sunday, September 13, 2026

GitHub Abused by Kimsuky Hackers Delivering Malware Through LNK Files

GitHub repositories for malware delivery through sophisticated weaponized LNK files, according to recent analysis by S2W’s Threat Intelligence Center, TALON.

This campaign demonstrates the group’s evolving tactics in leveraging trusted platforms to bypass security measures and establish persistent access to victim systems.

The attack chain begins with a malicious ZIP archive named “NTS_Attach.zip” containing a weaponized LNK file disguised as an electronic tax invoice PDF.

When executed, the shortcut file “전자세금계산서.pdf.lnk” triggers a PowerShell command that downloads and executes additional malicious scripts from attacker-controlled GitHub repositories.

The North Korea-backed APT group Kimsuky has been identified exploiting GitHub repositories.

The threat actors embedded hardcoded GitHub Private Tokens directly within their scripts to access private repositories, showcasing a sophisticated understanding of GitHub’s API infrastructure.

The primary payload, main.ps1, connects to the repository “hxxps://github[.]com/God0808RAMA/group_0721/” to download both decoy documents and additional malicious components.

The script employs dynamic file management techniques, replacing placeholder strings with timestamped values to create unique identifiers for each infection. This allows attackers to track and manage multiple compromised systems through their GitHub infrastructure.

Multi-Stage Persistence Mechanism

Kimsuky latest campaign establishes persistence through a complex scheduled task mechanism.

The malware creates “MicrosoftEdgeUpdate.ps1” in the victim’s %AppData% directory and establishes a scheduled task named “BitLocker MDM policy Refresh{DBHDFE12-496SDF-Q48D-SDEF-1865BCAD7E00}” that executes every 30 minutes.

This persistence mechanism enables continuous communication with the command and control infrastructure while appearing as legitimate system maintenance activity.

The info-stealer component, deployed as “temporary.ps1,” collects comprehensive system information including IP addresses, boot times, operating system details, hardware specifications, and running processes.

All collected data is systematically organized and uploaded to timestamped folders within the attacker’s GitHub repositories, creating an organized intelligence collection system.

Investigators analyzing the hardcoded GitHub tokens discovered nine private repositories associated with the campaign, including group_0717, group_0721, test, hometax, group_0803, group_0805, group_0811, fsc_doc, and repayment.

These repositories contained exfiltrated system logs, decoy documents, and files designed to appear as legitimate business communications such as payment reminders and audit reports.

Commit history analysis revealed the attacker’s email address “sahiwalsuzuki4[@]gmail.com” used during GitHub account creation.

Notably, test logs within the repositories showed evidence of remote administration tools including “xeno_rat_server” and clipboard monitoring processes, indicating the campaign’s broader objectives extend beyond initial reconnaissance.

Critical Security Implications

This campaign represents a significant evolution in APT tactics, demonstrating how threat actors can weaponize legitimate development platforms for malicious purposes.

The abuse of GitHub’s infrastructure provides attackers with reliable hosting, encrypted communications, and the ability to blend malicious traffic with legitimate development activities.

Organizations face increased challenges in detecting such activities due to the trusted nature of GitHub domains and the encrypted nature of API communications.

The use of timestamped file management and dynamic script updates allows attackers to maintain operational security while scaling their operations across multiple targets.

This approach enables real-time adaptation of malware payloads and collection strategies based on victim environments and defensive responses.

Security teams should implement comprehensive monitoring of GitHub API traffic, particularly PUT requests to “/repos/*/contents/” endpoints that could indicate data exfiltration activities.

Organizations should establish baseline monitoring for scheduled task creation, especially those with suspicious names or execution patterns consistent with malware persistence mechanisms.

Enhanced PowerShell logging and script block logging should be enabled across enterprise environments to detect suspicious script execution patterns.

Network security controls should scrutinize traffic to api.github.com and implement behavioral analysis to identify unusual repository access patterns that could indicate compromise.

Regular security awareness training focusing on LNK file risks and social engineering tactics remains crucial, as initial access vectors continue to rely on user interaction with seemingly legitimate documents and attachments.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Related Articles

Recent News