DPRK-Linked Hackers Use GitHub as C2 in Multi-Stage Attacks Targeting South Korea

GitHub has been seen to be used as command-and-control (C2) infrastructure by threat actors most likely connected to the Democratic People’s Republic of Korea (DPRK) in multi-stage operations against South Korean companies.

According to Fortinet FortiGuard Labs, the attack chain consists of obfuscated Windows shortcut (LNK) files that serve as the beginning point for dropping a PowerShell script that prepares the assault’s subsequent phase and a decoy PDF document. It has been determined that phishing emails are used to disseminate these LNK files.

The malicious PowerShell script runs quietly in the background while the victim is shown the PDF document as soon as the payloads are downloaded. The PowerShell script scans for active processes associated with virtual machines, debuggers, and forensic tools in order to execute checks to thwart analysis. The script ends right away if any of those processes are found.

If not, it extracts a Visual Basic Script (VBScript) and uses a scheduled task to set up persistence read more about DPRK-Linked Hackers Use GitHub as C2 in Multi-Stage Attacks Targeting South Korea.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *