Cyber & Technology — 2026-04-04

North Korean Hackers Abuse GitHub as C2 Infrastructure in Espionage Campaign Against South Korean Firms

FortiGuard Labs disclosed a North Korean state-sponsored campaign using GitHub as command-and-control infrastructure to target South Korean companies. The operation, active since 2024 but growing more sophisticated, uses malicious Windows shortcut files disguised as office documents. Victims see a decoy PDF while background scripts exploit PowerShell, VBScript, and WScript to compromise systems. Attribution points to Kimsuky, APT37, or Lazarus. GitHub's whitelisted status in corporate environments allows malicious traffic to blend with normal activity.

Analysis
GitHub as C2 is a known DPRK TTP, but the campaign's scaling against South Korean firms coincides with heightened Korean Peninsula tensions. The attribution uncertainty (Kimsuky, APT37, or Lazarus) may reflect collaboration across DPRK cyber units rather than genuine ambiguity. The terrain-matching technique in the LNK files parallels innovations in drone navigation; both seek to operate effectively in GPS-denied environments.
2 sources
  1. North Korean Hackers Abuse GitHub to Spy on South Korean Firms - Hackread
  2. North Korea Uses GitHub for Cyber Espionage Against South Korean Companies - News4Hackers

View in full brief →

UNCLASSIFIED // OPEN SOURCE