Kimsuky, a threat actor associated with North Korea, has been seen employing a novel technique in which they trick victims into launching PowerShell as an administrator before telling them to insert and execute malicious code they have supplied.
The Microsoft Threat Intelligence team stated in a series of postings released on X that the threat actor uses this technique by posing as a South Korean government official and gradually establishing a relationship with a victim before delivering a spear-phishing email with a [sic] PDF attachment.
The victims are tricked into clicking on a URL that contains instructions on how to register their Windows machine in order to see the alleged PDF document read more about North Korean Hackers Exploit PowerShell Trick to Hijack Devices in New Cyberattack.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
