DPRK-Linked Hackers Use GitHub as C2 in Multi-Stage Attacks Targeting South Korea
GitHub has been seen to be used as command-and-control (C2) infrastructure by threat actors most likely connected to the Democratic People's Republic of Korea (DPRK) in multi-stage operations against South Korean companies.
According to Fortinet FortiGuard Labs, the attack chain consists of obfuscated Windows shortcut (LNK) files that serve as the beginning point for dropping a PowerShell script that prepares the assault's subsequent phase and a decoy PDF document. It has been determined that phishing emails are used to disseminate these LNK files.
The malicious PowerShell script runs quietly in the background while the victim is shown the PDF document as soon as the payloads are downloaded. The PowerShell script scans for active processes associated with virtual machines, debuggers...

