Researchers discovered operational artifacts associated with a suspected Kimsuky campaign, revealing how the threat actor tested malware, handled infected-host data, and utilized public code repositories as command-and-control infrastructure This article explores files disguised legitimate. . The findings are part of an ongoing activity cluster labeled Operation GitPower, which researchers believe continues Kimsuky's earlier FlowerPower-style tactics involving malicious Windows shortcut files, PowerShell, and Git-based services.
The campaign targets policy, academic, diplomatic, international cooperation, and security-related organizations through spear-phishing emails. Victims receive ZIP archives containing malicious LNK shortcut files disguised as legitimate documents, including event materials, payment forms, legal files, research documents, and embassy correspondence. Examples of Spear Phishing Emails Mimicking Official Business Documents and Correspondence (Source: Genians) When an individual clicks on the LNK file, an obfuscated PowerShell command runs in the background.
The malware displays a legitimate-looking PDF document to reduce suspicion while downloading additional scripts and payloads from GitHub’s Raw Content service. It then creates hidden PowerShell files in temporary or AppData folders and establishes persistence through scheduled tasks that run at regular intervals. Indicators of Compromise IOC Type: C2 IP Address Description: The C2 IP address 112.216.9[.
]171 is embedded within fox.png, leopard.png, lion.png, and wolf.png payload variants used by the threat actor.












