Executive Summary
The Kimsuky threat group, linked to North Korea, is actively integrating artificial intelligence into its attack lifecycle, specifically within a campaign known as Operation GitPower. By employing AI agents such as 'opencode' and browser automation like HeadlessChrome, the group has moved toward the mass production of highly polished decoy documents. These decoys include artifacts like unreplaced LLM placeholders, suggesting a high-speed production pipeline with minimal human review.
Technically, the campaign relies on malicious LNK files distributed via ZIP archives. These LNK files execute obfuscated PowerShell loaders that utilize GitHub Personal Access Tokens (PATs) and Pastebin to retrieve follow-on payloads. The group has also implemented advanced analysis-evasion routines, checking for virtualization tools and specific sandbox usernames while using file size inflation and custom decoders to bypass static and automated security filters.
The expansion of decoy themes to include general corporate operations like insurance, interest payments, and store management indicates a broadening of Kimsuky's traditional targets. The use of localized AI environments (Ollama, GPT4All) for research suggests a long-term strategic commitment to automating data analysis and malware development, posing a heightened risk to financial, diplomatic, and security sectors.
