Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve

0
Medium
Published: 09/07/2026 (09/07/2026, 08:08:29 UTC)
Source: AlienVault OTX General

Description

The Kimsuky threat group is conducting Operation GitPower campaigns using malicious LNK files disguised as financial and business documents. These LNK variants leverage GitHub Personal Access Tokens (PAT) for command-and-control communications and deliver obfuscated PowerShell loaders. The campaign has evolved to include anti-analysis techniques, alternative C2 infrastructure via Pastebin, and AI-generated decoy content using the 'opencode' AI agent. Persistence is maintained through hidden scheduled tasks masquerading as legitimate software. Despite increased sophistication, endpoint behaviors remain detectable through behavioral correlation.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/07/2026, 16:08:36 UTC

Technical Analysis

Kimsuky continues its Operation GitPower campaigns with thirteen LNK file variants collected in August 2026. These files use hardcoded GitHub PATs to retrieve raw content for command-and-control, delivering obfuscated PowerShell loaders via custom decoders. The campaign has evolved with anti-analysis routines detecting virtualization tools, use of Pastebin as an alternative C2 channel, and diversified AI-generated decoys in PDF, XLSX, and PNG formats created with the 'opencode' AI coding agent and HeadlessChrome PDF conversion. Persistence is achieved through hidden scheduled tasks disguised as legitimate software such as BitLocker and MATLAB. Although evasion techniques and automation have increased, endpoint detection remains possible through behavioral correlation analysis.

Potential Impact

This campaign enables remote attackers to execute obfuscated PowerShell loaders on victim machines, potentially allowing unauthorized command execution and persistence. The use of GitHub PATs for C2 communications and AI-generated decoys increases the sophistication and stealth of the attacks. However, no known exploits are reported in the wild, and endpoint behaviors remain detectable, indicating that while the threat is advanced, it is not currently undetectable or uncontrollable.

Defensive Guidance

No official patch or fix is applicable as this is a threat actor campaign rather than a software vulnerability. Defenders should focus on detecting behavioral indicators related to obfuscated PowerShell execution, scheduled tasks masquerading as legitimate software, and unusual GitHub PAT usage. Monitoring for the provided file hashes and indicators can aid in detection. Endpoint detection and response solutions should leverage behavioral correlation to identify this activity. There is no vendor advisory indicating that no action is required; therefore, active monitoring and response are recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.genians.co.kr/blog/threat_intelligence/ai-agent-opencode"]
Adversary
Kimsuky
Pulse Id
6a9e70fd7eb74853a795cc57
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hashf1bd5817678f498966f033f61b617dee5c8e81191901fea7c4a89146bfe91091
hash10780939962b54addc9d31f57d80edfc
hash1523a2fcc901965ab4568d9fe829e4af
hash500e0bc0d7579fb338912770964076fe
hash685bfc6b2c29fbc16cfad908894add55
hash7a53089053b1381742856a5cf2b95f8b
hash8db2f20b719dcb7029d6296505622093
hash900e832c10d851bbdef3fb191a15db0e
hasha2015665a3e18bf0ef86e3931245c7e6
hashbb88940e915b11f6330b7446f6037f5b
hashce5932b88f879f26006df81f2fa7667e
hashd0894d4626aae0f96d6b84ca3bb71a36
hashe50f2ae7fb03675a1ef58b1cf9cda6d1
hashf648bdd3c2cd902e239149de86d43e8f
hash441b709b1a57353a7b127d9a35b5002eee7e6efb
hashf72bd8bde005b8646d64f6a516407b6f9d2c680a
hash8d0aad27440fb29f9ab5f1af0f7977ed332d945d4bbeb7af0a96e07ac24eaaff

Threat ID: 6a9eddbbacd9273b49e07701

Added to database: 09/07/2026, 15:52:27 UTC

Last enriched: 09/07/2026, 16:08:36 UTC

Last updated: 09/07/2026, 18:21:46 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses