Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve

◈ Key Findings

  • Evidence of follow-on distribution using malicious LNK files contained in ZIP archives identified in Kimsuky-linked attack activity
  • Traces of the AI agent "opencode" identified in decoy PDF metadata, showing the continued use of AI and LLMs to mass-produce decoys
  • All LNK files configured to launch PowerShell, with encrypted loaders concealed within lengthy execution arguments
  • Decoy documents and follow-on PowerShell commands retrieved from GitHub Raw Content paths using a GitHub PAT
  • Anti-analysis logic designed to detect analysis tools and virtualization processes and terminate execution when specific conditions are met
  • Need to strengthen EDR-based detection and threat hunting for the abuse of LNK files, PowerShell, and GitHub

 

Article Link: Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve