<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=939333007162424&amp;ev=PageView&amp;noscript=1">
 

    Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM

    ◈ Key Findings

    • Observed indications that the Kimsuky group built and operated local LLM environments using Ollama, GPT4All, and Msty.
    • Assessed to be in the phase of accumulating technologies and capabilities to integrate AI across its overall attack operations.
    • Identified indicators exhibiting North Korea-linked characteristics, such as "Arirang", "싸이트", "가입리력", and "로출되였는지".
    • Continued targeted attacks against foreign diplomatic missions, as well as the military, security, and virtual asset sectors.
    • Abused Git-based repositories as C2 infrastructure and distribution channels for encrypted AsyncRAT payloads.
    • Highlighted the need to strengthen behavior-based EDR detection and threat hunting against the abuse of LNK files, PowerShell, and GitHub.

     

     

    1. Executive Summary

    Genians Security Center has been continuously tracking GitHub- and GitLab-based attack activity assessed to be associated with Kimsuky, a cyber threat group known to operate under North Korea's Reconnaissance General Bureau.

    This activity is not a newly emerged standalone campaign, but part of a continuation of Kimsuky's attack operations observed over several years.

    In particular, it shares key characteristics with the "FlowerPower" campaign disclosed in 2023, including the continued use of a PowerShell-based execution framework and the active abuse of Git-based repositories. It also shows links to the attack tactics identified in the 2024 report, "Analysis of a Hacking Campaign Disguised as a New Year Opinion Column."

    Accordingly, this report refers to the activity as Operation GitPower and continues to track it as an attack operation that inherits the existing FlowerPower attack flow while incorporating a Git-based command-and-control (C2) operational structure.

    For many years, the Kimsuky group has conducted various spear phishing attacks targeting professionals and organizations in the fields of policy, academia, international cooperation, diplomacy, and security research. Malicious files disguised as materials related to international events, research reports, invitations, honorarium payments, investigative cooperation requests, meeting materials, and financial and legal documents continue to be observed.

    Recent attacks are primarily carried out through malicious LNK files contained in ZIP archives. When a user executes the LNK file, obfuscated command-line arguments are processed, and an embedded PowerShell loader is executed.

    Cases have also been identified in which documents related to virtual assets and finance, assessed to have been created using generative AI, were used as attack lures. These documents use natural language, a highly polished structure, and formats similar to actual business materials to increase user trust and induce the execution of malicious files.

    Genians Security Center has also identified multiple indications that the Kimsuky group has used and experimented with various AI technologies and tools, including local LLMs, RAG, and Cursor.



    [Figure 1-1] AI-Enabled Attack Flow

    [Figure 1-1] AI-Enabled Attack Flow

     

    The threat actor was found to use various obfuscation techniques, including Base64 encoding, string splitting, and custom decoding routines, to conceal the actual behavior.

    This threat intelligence report is not limited to a single sample. It is based on attack behaviors and infrastructure operation characteristics repeatedly observed across multiple variants and is intended to support the development of detection policies, threat hunting, and enhanced incident response capabilities against future attacks from the same threat family.

    Security teams within enterprises and organizations should correlate and detect abnormally long execution arguments in LNK files, custom Base64 decoding, hidden PowerShell execution, scheduled tasks, access to the GitHub Raw Contents API, the use of PATs unrelated to business operations, and encrypted .NET payloads disguised with image file extensions.

     

     

    2. Case Study

    2-1. Initial Access

    The initial infection begins when a user downloads a ZIP archive distributed by the threat actor through email or other channels and executes the LNK file contained within it.

    The archive contains LNK shortcut files that use document icons and filenames resembling materials used in actual business operations, such as official documents, research materials, honorarium payment request forms, media articles, and embassy correspondence.

     

    [Figure 2-1] Examples of Spear Phishing Emails Disguised as Legitimate Business Documents and Official Correspondence

    [Figure 2-1] Examples of Spear Phishing Emails Disguised as Legitimate Business Documents and Official Correspondence

     

    The confirmed spear phishing email cases show how the threat actor uses various business scenarios, including honorarium payment requests, legal documents, requests to review media articles, and urgent embassy correspondence, to induce users to execute the malicious files.

     

    2-2. Analysis of AI-Based Decoy Documents

    The threat actor has previously reused documents stolen or obtained during earlier attacks as decoy documents in subsequent spear phishing campaigns. However, since 2026, a pattern of attacks has been observed in which documents created using generative AI are continuously used as decoy files.

    AI can generate highly polished documents on a wide range of topics within a short period of time, making it a highly efficient tool for threat actors.

    This change is noteworthy because it goes beyond a shift in how decoy documents are created and demonstrates that AI can enable the automation and large-scale production of social engineering attacks.

    Although the decoy PDF documents obtained during the analysis covered different topics, including virtual assets, financial investment, and game development, they showed a high degree of similarity in their structure and writing style.

    Analysis of the PDF metadata and document structure identified multiple indicators suggesting that an automated document creation environment using generative AI had been used.

     

    [Figure 2-2] Examples of PDF Decoy Documents Used in Actual Attacks

    [Figure 2-2] Examples of PDF Decoy Documents Used in Actual Attacks

     

    First, the metadata of the two English-language decoy documents listed "python-docx" as the Author and "WPS 文字" as the Creator.

    python-docx is a widely used open-source library for automatically generating Microsoft Word documents in Python environments, while WPS 文字 refers to the word processor component of WPS Office developed by the Chinese company Kingsoft.

     

    [Figure 2-3] Metadata Information in the English-Language Decoy Documents

    [Figure 2-3] Metadata Information in the English-Language Decoy Documents

     

    The two documents were also found to have been created and modified at 5:00:04 a.m. on March 11, 2026, and 5:00:44 a.m. on March 24, 2026, respectively. In both documents, the creation and modification timestamps were identical. Although they were produced approximately two weeks apart, both were created at 5:00 a.m., with a difference of only about 40 seconds between their timestamps.

    In another case, a malicious shortcut (LNK) file with a name that could easily be mistaken for legitimate investment strategy materials, such as "OOOO July 2026 Practical Strategy Pack.pdf.lnk", was distributed.

    The file employed social engineering techniques by imitating the document format and content distributed by a Korea-based fintech platform that provides AI-powered investment strategy services, leading users to perceive it as a legitimate document.

    For reference, the service operator recently issued a warning about phishing emails impersonating the company and using titles such as "Practical Strategy Pack for Real-World Application". In a separate notice titled "Notification and Apology Regarding the Exposure of Personal (Credit) Information", the company also disclosed that some customer information had been exposed.

     

    [Figure 2-4] Decoy Document Containing AI Investment Strategy Content

    [Figure 2-4] Decoy Document Containing AI Investment Strategy Content

     

    The same pattern is also evident in the document's visual design. Each page maintains consistent layouts, color schemes, table structures, margins, and section placement rules.

    Various emoji elements are used in the title areas, a style rarely found in conventional financial investment materials.

    These design patterns closely resemble the default templates provided by recent generative AI-based document creation services and web-based presentation tools.

     

    2-3. Analysis of an LNK Case Using an International Education Event Concept Note

    The same campaign also included an attack disguised as a proposal for an international education event. The filename included a PDF extension to make the file appear to be a concept note for an international youth education event.

    The command-line arguments field in the LNK properties contains a very long string, which is used to conceal the actual PowerShell script or store data required for decryption.

     

    [Figure 2-5] LNK File Properties

    [Figure 2-5] LNK File Properties

     

    The LNK command-line arguments consist of a PowerShell command approximately 3,800 characters long.

    In particular, approximately 300 consecutive space characters are inserted before the actual PowerShell script. This technique prevents the key portion of the command-line arguments from being displayed in the Windows shortcut properties window.

    The LNK file also contains the following description information:

    • Type: Hangul Document
    • Size: 2.84 KB
    • Date modified: 10/20/2023 11:23

    However, the actual file is an LNK file approximately 304 KB in size, and the document type, size, and modification date recorded in the description do not match its actual properties.

     

    [Figure 2-6] LNK File Command-Line Arguments

    [Figure 2-6] LNK File Command-Line Arguments

     

    The core data in the command-line arguments is Base64-encoded. However, instead of directly calling the commonly used "[Convert]::FromBase64String()" function, the threat actor used a custom decoder that implements the Base64 character table and bitwise operations.

    The LNK arguments directly decode the Base64-encoded PowerShell script, save it, and execute it through a hidden PowerShell process.

    • %TEMP%\poqpwoqwdjoweij.ps1

    The decoded first-stage PowerShell script first specifies the following file path in the system's temporary directory.

    • %TEMP%\CONCEPT NOTE of 2026 I-ASEAN Global Youth Camp.pdf

    It then downloads the "riudxkfngidruhkr.pdf" file through GitHub's Raw Content service, saves it to the specified path, and immediately opens it. As a result, the victim may believe that the file has opened normally, while subsequent malicious activity proceeds in the background as the PDF is displayed.

    The analyzed download path is constructed through string concatenation in the following format.

    • https://raw.githubusercontent.com/<Account>/<Repository>/main/<Filename>

    The threat actor divided the URL into multiple strings, such as "ht" + "t" + "ps", and similarly split the account and repository names into multiple short strings before concatenating them. This structure is intended to evade URL-based detection and static string analysis.

    The request header also contains a hardcoded access token required for GitHub API access. The token has since been revoked.

    After displaying the legitimate PDF, the script creates the following PowerShell file in the "%AppData%" directory. This file serves as an intermediate PowerShell script that is repeatedly executed through a scheduled task.

    • %AppData%\irujkdnjhgttrhdkfdu.ps1

    The malware then registers a hidden scheduled task with the following name. The task first runs approximately five minutes after registration and repeats at 30-minute intervals thereafter.

     

    • ZHUYHJGTYTFSUHIPOKLKHJHUYGVHGNFH

     

    [Figure 2-7] Commands in "irujkdnjhgttrhdkfdu.ps1"

    [Figure 2-7] Commands in "irujkdnjhgttrhdkfdu.ps1"

     

    The intermediate script downloads the "priujghtjytfcghffgt.txt" file from GitHub, creates and executes the following file in the "%AppData%" directory, and then deletes it.

    • %AppData%\lpieuysjfgtrja.ps1

     

    [Figure 2-8] Commands in "lpieuysjfgtrja.ps1"

    [Figure 2-8] Commands in "lpieuysjfgtrja.ps1"

     

    When this command is executed, it collects the IP address from an active network adapter on the infected system, combines it with the current time, generates a filename in the format "<IP address>-<MMDD_HHMM>-XXX-kkk.txt", and creates the corresponding TXT file in the "%APPDATA%" directory.

    It then downloads "bhjfjkfgrtwehjbfgcf.txt" from GitHub, creates and executes "ms_update.ps1" in the "%AppData%" directory, and deletes it afterward.

    • %AppData%\ms_update.ps1

     

    [Figure 2-9] Commands in "ms_update.ps1"

    [Figure 2-9] Commands in "ms_update.ps1"

     

    This script collects the IP address from an active network adapter on the infected system, combines it with the current time, generates a filename in the format "<IP address>-<MMDD_HHMM>-0956_info.txt", and creates the corresponding TXT file in the "%APPDATA%\Microsoft" directory.

    Through this process, the threat actor identifies the system based on the infected host's IP address and the script execution time. The script also collects detailed system information, including the operating system version and architecture, system configuration, PC type, operating system installation and boot history, and a list of running processes. This information is used to assess the infected environment and support subsequent attacks.

     

    2-4. Analysis of AsyncRAT Distribution Using Git-Based C2 Infrastructure

    Attack cases involving the use of Git repositories as command-and-control (C2) infrastructure continue to be observed. The threat actor operates these attacks flexibly by replacing scripts and payloads (RATs) stored in the repositories as needed.

    During the analysis, Genians Security Center identified multiple public GitHub repositories operated by the threat actor. One repository contained not only configuration files and PowerShell scripts, but also various payloads used in subsequent attacks.

     

    [Figure 2-10] Files Stored in a Public GitHub Repository

    [Figure 2-10] Files Stored in a Public GitHub Repository

     

    In particular, multiple files that appeared to be legitimate images, including "apple.png", "fox.png", "lion.png", "rabbit.png", and "wolf.png", were identified. Analysis confirmed that these files were not actual images, but RC4-encrypted .NET-based AsyncRAT payloads.

    The threat actor stored "rTom.exe_r" together with AsyncRAT payloads disguised as the image files "apple.png" and "rabbit.png" in the Git repository and used them in attacks. The IP address "169.254.33[.]137" was also observed being used for testing, indicating an operational security failure (OPSEC failure).

     

    [Figure 2-11] Code Analysis of "rTom.exe_r"

    [Figure 2-11] Code Analysis of "rTom.exe_r"

     

    In contrast, "fox.png", "leopard.png", "lion.png", and "wolf.png" were found to use the C2 address "112.216.9[.]171", an IP address located in South Korea.

     

    [Figure 2-12] AsyncRAT with the C2 Address Changed to "112.216.9[.]171"

    [Figure 2-12] AsyncRAT with the C2 Address Changed to "112.216.9[.]171"

     

    2-5. Threat Actor's Research and Experimentation with AI

    This section presents the key findings of this report.

    Genians Security Center conducted months of tracking and log analysis on the infrastructure utilized as C2 in this campaign.

    During this process, it was confirmed that the threat actor was using the C2 infrastructure not only as a command-and-control server, but also as an environment for malware development and testing, stolen data management, and AI technology research.

    Based on these findings, the threat actor associated with the state-sponsored hacking group Kimsuky is assessed to have continuously researched ways to actively incorporate AI technologies into actual threat activities, including malware development and the advancement of attack techniques, rather than merely experimenting with them.

     

    [Figure 2-13] Evidence of Malware Development Observed in C2 Infrastructure Logs

    [Figure 2-13] Evidence of Malware Development Observed in C2 Infrastructure Logs

     

    2-5-1. Establishment of a Local LLM (Large Language Model) Execution Environment

    The first indication identified was that the threat actor had directly established multiple types of local LLM execution environments within its own infrastructure.

    Because the local approach prevents conversation data from being transmitted to external AI services, it reduces the risk of external exposure, making it a particularly attractive option for a state-sponsored threat actor.

    The logs showed evidence of all three major local LLM execution tools.

    First, traces of Ollama were identified, including the presence of the "id_ed25519" and "id_ed25519.pub" key files in the "C:\Users\Administrator\.ollama" folder.

    Ollama is a free, open-source tool for running and managing local LLMs. It allows users to run and manage LLMs directly on their PCs or servers and use various AI models without an internet connection.

    It supports the download and local execution of various LLMs, including Meta's Llama, Mistral AI's Mistral, Google's Gemma, Alibaba Cloud's Qwen, and DeepSeek's DeepSeek. It can also be easily integrated with other programs through a command-line interface (CLI) and local APIs.

     

    [Figure 2-14] Traces of Ollama Installation

    [Figure 2-14] Traces of Ollama Installation

     

    The key files observed in the logs are unique authentication keys automatically generated when Ollama is first launched. Their presence supports the assessment that the program was not merely downloaded, but was actually installed and executed.

    Second, the "LocalDocs-Setup-0.4.2.exe" installation file for GPT4All and the "AppData\Local\nomic.ai\GPT4All" folder created after installation were identified.

    GPT4All is a free, open-source local LLM execution platform developed by Nomic AI. It allows various open-source AI models to run in a local environment and supports question answering based on user-owned documents through its LocalDocs feature using retrieval-augmented generation (RAG).

     

    [Figure 2-15] Traces of GPT4All Installation

    [Figure 2-15] Traces of GPT4All Installation

     

    Third, traces of Msty were identified in two locations.

    The installation file "MstyStudio_x64.exe" was found in the "C:\Users\Administrator\Pictures" folder, while "msty-local-studio.exe", which is responsible for running local AI models after installation, was found in the "AppData\Local\Programs\MstyStudio\localai" path.

     

    [Figure 2-16] Traces of Msty Installation

    [Figure 2-16] Traces of Msty Installation

     

    Msty is an AI desktop application designed to manage and use local and cloud-based LLMs through a single interface.

    It can integrate local LLM runtime engines such as Ollama with various cloud AI services, including ChatGPT, Claude, and Gemini. It also provides features such as document-based retrieval-augmented generation (RAG), AI agent configuration, integration with external tools and data sources through the Model Context Protocol (MCP), and knowledge base and conversation management.

    The fact that all three tools left installation traces is an important indicator that the threat actor did not merely test a single tool by chance, but broadly compared and evaluated multiple approaches to running AI models locally.

     

    2-5-2. Evidence of Actual Use of Document-Based Knowledge through RAG

    More notably, evidence showed that these tools were not merely installed, but were actually configured and used.

    A database file named "localdocs_v3.db" was observed in the GPT4All folder. This file is created when GPT4All's "LocalDocs" feature is configured.

    LocalDocs implements retrieval-augmented generation (RAG). RAG is a method in which an AI system first searches a predefined collection of documents for information relevant to a question and then generates a response based on the retrieved content.

    In simple terms, while a conventional chatbot responds using only the knowledge on which it was trained, RAG enables it to answer based on specific documents provided by the user, such as internal materials or stolen documents.

    The presence of this database file therefore provides direct evidence that the threat actor attempted to connect documents in its possession to an AI system and use them as a knowledge source.

    The "cache\models3.json" file in the same folder contains a list of AI models used and managed by GPT4All, providing an indication of which language models were selected and operated.

     

    2-5-3. Collection of Libraries for AI Agent and Automation Development

    The threat actor did not stop at using ready-made AI applications. It also collected a large number of development components, or libraries, intended to integrate AI capabilities directly into programs under its own development.

    Multiple NuGet packages were identified in the "Pictures\zzz\nupkg" path.

    Because this path is not typically used to store development-related files, the threat actor appears to have used a directory that was unlikely to attract user attention in order to make the files less noticeable.

    This appears to have been an attempt to conceal malicious activity by disguising the files as legitimate packages used in development environments.

     

    [Figure 2-17] Traces of NuGet Package Installation

    [Figure 2-17] Traces of NuGet Package Installation

     

    LLaMaSharp and GPU acceleration backends, including "cuda11" and "cuda12", were also identified.

    LLaMaSharp is a library that enables LLMs to run within C# applications in a local environment, while GPU backends use graphics processing units to accelerate AI model inference.

    "LangChain.providers.llamasharp", "Microsoft.SemanticKernel", and "Microsoft.Agents.AI" were also identified.

    These are representative AI application and agent development frameworks used to search documents with AI models through RAG, combine multiple functions, and enable AI systems to plan multiple steps and use various tools.

    "Microsoft.Extensions.AI" was also included. This library provides a common interface that allows various AI models, including OpenAI and Ollama, to be used in a consistent manner.

    The "OpenAI" and "Azure.AI.OpenAI" packages were also present. These packages are used to directly call and integrate commercial AI services, such as OpenAI and Azure OpenAI Service, within applications.

    The fact that development components spanning "local AI execution → document retrieval (RAG) → automated agents → external AI integration" were collected together strongly suggests that they were not gathered out of simple curiosity, but for the direct development of an AI-based tool designed for a specific purpose.

     

    2-5-4. Evidence of Speech-to-Text (STT) Tools and Data Processing

    The logs also contained materials related to speech-to-text (STT), or speech recognition, which converts spoken audio into text.

    "faster-whisper.7z" and "whisper.7z" contain OpenAI's publicly released speech recognition model "Whisper" and its high-speed implementation. These tools are used to automatically transcribe recorded audio files into text.

    A Korean-language training file titled "음성 파일에서 텍스트를 뽑아오자(with faster whisper).mhtml" was stored in the same folder, indicating that the threat actor studied how to use this feature for practical purposes.

     

    [Figure 2-18] Files Related to the AI Development Environment Identified in C2 Storage Logs

    [Figure 2-18] Files Related to the AI Development Environment Identified in C2 Storage Logs

     

    Tools that automatically convert speech into text can be used to quickly extract and organize relevant information from large volumes of calls, meetings, and media content. As a result, they could be abused to process and analyze materials stolen or collected from compromised systems.

     

    2-5-5. Learning Materials and Development Environment: Basis for Assessing the Activity as Being in the "Research and Knowledge Acquisition Stage"

    The strongest evidence supporting this assessment is the large volume of Korean-language learning materials left by the threat actor. Multiple technical resources saved as complete webpages in the ".mhtml" format were found in the "Pictures\zzz" folder.

    These materials primarily consisted of Korean blog and community webpages containing information on ML, AI, and LLMs.

    One point must be made clear: no evidence was found in the logs indicating that the observed activity had progressed to the stage of training new AI models.

    Neither the large training datasets required for independent model training nor model files produced as training outputs, such as fine-tuning results, were observed in the logs.

    Instead, the evidence showed that the threat actor was focused on learning and experimenting with ways to integrate publicly available AI models and frameworks into its own tools and programming environment, primarily C# and .NET.

    In other words, at the time of observation, the threat actor was not at the stage of "building AI itself", but rather at the stage of "researching and acquiring the knowledge needed to integrate existing AI into its attack activities".

    These findings show that the threat actor is continuously researching AI technologies and building the capabilities required to integrate them into attack tools. Attention should therefore be paid to the possibility that these efforts could develop into new AI-enabled attack techniques.

    Overall, the threat actor had established and configured local LLM runtime environments using Ollama, GPT4All, and Msty, tested RAG for document-based question answering, and systematically collected components and learning materials required for AI agent, speech translation, and machine learning development.

    As described above, this provides concrete evidence that the Kimsuky-affiliated threat actor is moving beyond one-off experimentation with AI and is continuously preparing to integrate the technology into actual attack capabilities, including malware development, data analysis, and the advancement of attack techniques.

    However, the evidence identified to date remains focused on the use and integration of existing AI technologies rather than independent model training. It is therefore necessary to continue monitoring changes in the scope of AI use and the evolution of related attack techniques.

     

     

    3. Threat Attribution

    3-1. Evidence of LNK Creation Tool Use

    While analyzing various artifacts left by the threat actor, Genians Security Center also identified evidence that an LNK file creation tool had been stored.

     

    [Figure 3-1] Record of the "lnk-builder" Tool Being Stored

    [Figure 3-1] Record of the "lnk-builder" Tool Being Stored

     

    The collected logs showed that a ZIP archive had been extracted and that the "lnkbuilder.exe" file was present.

     

    [Figure 3-2] "lnkbuilder.exe" File

    [Figure 3-2] "lnkbuilder.exe" File

     

    Analysis confirmed that the file matched the CLI-based LNK File Builder distributed through a GitHub repository published in September 2023. The use of a publicly available tool has limited value for attribution, but it is still worth noting as a reference point in tracing the lineage of this technique.

    North Korea-linked threat actors that primarily target South Korea, including Kimsuky and APT37, have used LNK-based attack techniques for an extended period.

    In particular, APT37's use of an internally developed LNK creation tool in actual attacks was first disclosed in the June 2023 report, "Emergence of an APT37 Attack Targeting macOS Users in South Korea."

     

    [Figure 3-3] LNK Builder Used by the APT37 Group

    [Figure 3-3] LNK Builder Used by the APT37 Group

     

    3-2. Same RTF Header Manipulation and Gzip Recovery Method

    During the investigation of multiple Git-based C2 infrastructures, a technique was identified in which file headers were modified to resemble the Rich Text Format (RTF) when delivering additional payloads.

    This technique is identical to the case identified in the February 2024 report, "Analysis of a Hacking Campaign Disguised as a New Year Opinion Column." The campaign was previously attributed to the Kimsuky group.

     

    [Figure 3-4] Command for Restoring the Modified RTF Header to a Gzip Header

    [Figure 3-4] Command for Restoring the Modified RTF Header to a Gzip Header

     

    The payloads are concealed under various filenames and have headers modified to resemble RTF files. After being downloaded, their headers are restored to the Gzip header values "0x1F, 0x8B, 0x08, 0x00, 0x00, 0x00, 0x00", after which the payloads are decompressed and loaded.

     

    3-3. Evidence of Cursor AI Use in Kimsuky Infrastructure

    In April, Fortinet disclosed a North Korea-linked attack campaign that used GitHub as C2 infrastructure in its report, "DPRK-Related Campaigns with LNK and GitHub C2".

    While analyzing logs associated with the GitHub account used in the campaign, Genians Security Center identified evidence that the threat actor edited the "Pumpfun-AI-Attack-Defence-Requirements.md" file in Cursor AI and then opened the generated "view.pdf" file in Google Chrome for review.

     

    [Figure 3-5] Logs Showing the Use of "view.pdf" and Cursor AI

    [Figure 3-5] Logs Showing the Use of "view.pdf" and Cursor AI

     

    Multiple Cursor AI installers were also identified in the download path logs.

     

    [Figure 3-6] Cursor AI Installers Stored in the Downloads Folder

    [Figure 3-6] Cursor AI Installers Stored in the Downloads Folder

     

    3-4. Chinese-Language WPS Office Environment and System Manufacturer "Arirang"

    The threat actor was found to have opened the "Marketing-Service-Agreement-Pumpfun-AI-Attack-Defence.docx" document using the Chinese-language version of WPS Office 2019.

    This finding is consistent with the creation information previously identified in the PDF metadata and supports the assessment that the threat actor used a Chinese-language WPS Office environment in its actual development environment.

     

    [Figure 3-7] Record of the Document Being Viewed in WPS Office 2019

    [Figure 3-7] Record of the Document Being Viewed in WPS Office 2019

     

    A record was also found showing that, while reviewing the "Test-com1.json" file in Cursor AI, the threat actor copied a GitHub API response to the clipboard.

    The JSON contained the repository owner "brandonleeodd93-blip", the commit author's email address "brandonleeodd.93@gmail[.]com", and an upload record for the infection information file "172.16.11[.]141-0313_0319-0956_info.txt", which included the internal IP address "172.16.11[.]141".

    This record shows that the threat actor verified the infection information upload function in its own test environment, which exactly matches the behavior of the information collection script analyzed earlier.



    [Figure 3-8] Logs Showing GitHub C2 Testing Using Cursor AI

    [Figure 3-8] Logs Showing GitHub C2 Testing Using Cursor AI

     

    Another notable finding was that the system manufacturer was listed as "Arirang" in the threat actor's logs.

    "Arirang" is not currently known as a PC manufacturer in South Korea. However, "Arirang" has been introduced in North Korea as a brand of tablet PCs and smartphones.

    This information alone is not sufficient to determine the system's actual manufacturer or operating environment.

     

    [Figure 3-9] "Arirang" Manufacturer Information and Process Names

    [Figure 3-9] "Arirang" Manufacturer Information and Process Names

     

    The running processes also included AnyDesk, a remote access application, Astrill VPN, a VPN client, and Cursor, an AI-powered development tool.

    Astrill VPN has been repeatedly observed as an indicator associated with North Korea-linked threat actors in multiple public threat intelligence reports, including campaigns involving North Korean IT workers seeking employment under false identities. Although it is not conclusive evidence on its own, when combined with the Chinese-language environment, the "Arirang" manufacturer entry, and the accumulation of Korean-language learning materials, it serves as a contextual indicator supporting the assessment of the operator's background.

     

    3-5. Evidence of Dubeolsik Korean Keyboard Input and Multiple North Korean Expressions

    During the log analysis, Genians Security Center identified that input recorded as English key values consistently corresponded to the KS X 5002 Dubeolsik Korean keyboard layout, the national standard used in South Korea. Based on this correspondence, the input could be reconstructed as sentences typed while Korean input mode was enabled.

    Both North and South Korea use national keyboard standards based on the Dubeolsik layout. However, South Korea uses the KS X 5002 standard, while North Korea uses the KPS 9256 standard. Although the two standards use similar consonant and vowel sections and input methods, the placement of certain individual characters differs. North Korea-linked threat actors may nevertheless use the South Korean Dubeolsik keyboard layout when operating Korean-language Windows environments or creating documents and content targeting South Korean users.

    When the input recorded as English key values was converted according to the standard South Korean Dubeolsik keyboard layout, it was restored as Korean sentences.

    In its operating environment, the threat actor wrote a question in Korean asking how to disable the Report feature in Microsoft Defender and then translated it into English using Google Translate.

    Reproduction testing confirmed that the Google Translate output exactly matched the English text recorded in the clipboard logs.

     

    [Figure 3-10] Keystroke Artifacts Entered Using a Korean Keyboard Layout

    [Figure 3-10] Keystroke Artifacts Entered Using a Korean Keyboard Layout

     

    Subsequently, consecutive Ctrl+V and Enter inputs were recorded in a "ChatGPT - Google Chrome" window, confirming that the translated English sentence was submitted as a ChatGPT prompt.

    This suggests that the threat actor may have preferred English prompts to obtain more accurate and useful responses to technical questions or to make use of English-language technical resources.

     

    Log Entry (Cleaned)

    Microsoft Defenderdptj Reportrlsmddmf tjfwjdgowpgkfuaus djEjgrp gkdudi gksmsrk?

    Korean Keyboard Layout (Converted)

    Microsoft Defender에서 Report기능을 설정해제하려면 어떻게 하여야 하는가?

    Google Translate Output (English)

    How do I disable the Report feature in Microsoft Defender?

    [Table 3-1] Evidence of Korean Keyboard Use and Converted Content #1

     

    The log analysis also identified evidence that the threat actor typed sentences using the Dubeolsik Korean keyboard layout asking whether personal information had been exposed, including wallet information, Gmail account information, and website registration history.

     

    [Figure 3-11] Logs Containing North Korean Expressions

    [Figure 3-11] Logs Containing North Korean Expressions

     

    After the log entries were cleaned and converted using the Korean keyboard layout, the resulting text was as follows and matched the English Google Translate output contained in the original logs.

     

    Log Entry (Cleaned)

    ghrtl durldp wlrkqwjdqh(SeedEhsms rkdlqdkagh emd), Gmailwjdqh(ID, dkagh emd),

    Tkdlxmrkdlqflfurdmf qlfhtgotj rodlswjdqhemfdl fhcnfehlduTsmswl dkfdkqhkwntlqtldh.

    rncpwjrdmfh qnstjrgkftnfhr whgtmqslek.

    eocndgkwlsms aktpdy.

    qnxkrgkqslek.

    Korean Keyboard Layout (Converted)

    혹시 여기에 지갑정보(Seed또는 가입암호 등), Gmail정보(ID, 암호 등),

    싸이트가입리력을 비롯해서 개인정보들이 로출되였는지

    알아봐주십시오.

    구체적으로 분석할수록 좋습니다.

    대충하지는 마세요.

    부탁합니다.

    Google Translate Output (English)

    Please check if any personal information, including wallet details (Seed or sign-up passwords, etc.), Gmail information (ID, password, etc.), and site sign-up history, has been exposed here.

    The more detailed the analysis, the better.

    Please do not do it haphazardly.

    Thank you.

    [Table 3-2] Evidence of Korean Keyboard Use and Converted Content #2

     

    When the input logs recorded as English key values were reconstructed according to the Dubeolsik Korean keyboard layout, North Korean vocabulary and spelling patterns, including "싸이트", "리력", and "로출되였는지", were repeatedly identified.

    In standard South Korean usage, these would be written as "사이트", "이력", and "노출되었는지", respectively.

    These recurring vocabulary and spelling patterns serve as digital profiling indicators of the threat actor's regional and cultural background, as well as linguistic clues supporting threat attribution.

    This is a threat intelligence analysis methodology used to identify an actor's linguistic background and operating environment based on region-specific vocabulary, spelling conventions, and language usage context.

     

    [Figure 3-12] Example of Mapping English Keys to Korean Keyboard Characters

    [Figure 3-12] Example of Mapping English Keys to Korean Keyboard Characters

     

    In particular, the same spellings were retained even after repeated corrections using the Backspace key, indicating that they were not simple typographical errors but rather spelling habits internalized by the threat actor.

    The final English text followed an imperative structure that specified the subject of analysis, listed the items to be queried, and requested a detailed analysis.

    This structure is well suited for use as a prompt submitted to an AI service. Although no keystroke or window-switching records were identified that could confirm the sentence was pasted into and submitted to a specific AI service after being recorded in the clipboard, this possibility cannot be ruled out.

     

    3-6. Multiple Instances of North Korean Terminology Identified

    Analysis of search records exposed on the C2 server identified numerous examples of North Korean vocabulary and expressions.

    The records primarily contained searches and queries related to foreign currency earning activities. A usage pattern was also observed in which the author translated Korean-language queries using Google Translate and then entered the translated text into ChatGPT.

     

    [Figure 3-13] Examples of Search and Google Translate Records

    [Figure 3-13] Examples of Search and Google Translate Records

     

    Multiple search records and activity traces related to virtual assets were also identified.

    In particular, queries such as "btc를 리용하는 사용자들을 어디서 검색할 수 있습니까?" were found. This may represent reconnaissance conducted to collect information on Bitcoin users or support virtual asset-related activities.

    Queries related to document exploit techniques were also identified, including "해커들이 Doc exploit를 리용하여 어떻게 공격하는지 구체적으로 알고싶습니다." Linguistic characteristics were observed in these queries, including the use of multiple expressions known to be used in North Korea.

     

    [Figure 3-14] Sentences Containing North Korean Vocabulary

    [Figure 3-14] Sentences Containing North Korean Vocabulary

     

     

    4. Conclusion

    4-1. Threat Campaign Conclusion

    The initial access techniques used in this campaign do not differ significantly from Kimsuky's established tactics. Spear phishing, LNK files, PowerShell, decoy documents, and combinations of multiple C2 servers have been repeatedly observed for years.

    However, the substantive change highlighted in this report lies elsewhere.

    What was observed in the threat actor's infrastructure was not merely evidence of several documents being created with AI, but a consistent process of capability development: establishing local LLM runtime environments, configuring RAG based on documents in the actor's possession, collecting AI agent development frameworks, and acquiring libraries for integration with external commercial AI services.

    The following three combinations are particularly important for anticipating how the threat may evolve.

    • (RAG + stolen documents) This combination could be used to automatically identify valuable information within large volumes of stolen data, reducing the analytical bottleneck that follows data theft.
    • (STT + call and meeting recordings) This combination converts stolen audio data into text, making it searchable and available for analysis.
    • (AI agent frameworks + C#/.NET) These frameworks are combined with the programming languages actually used by the threat actor, clearly indicating an intent to integrate AI capabilities into its own tools.

    However, no evidence of independent model training has been identified at this time. The observed activity remains focused on applying AI to malware development and attack operations.

    The defensive implications are clear. Assessing threats based solely on the quality of decoy documents is no longer an effective defensive approach. The use of generative AI is rapidly weakening traditional digital profiling indicators, such as unnatural translated language, poor formatting, and spelling errors.

    Defensive strategies must therefore shift from content-based assessment to behavior-based detection, and this should serve as the fundamental premise of security recommendations.

    In addition to indicator of compromise (IoC)-based detection, organizations should contextually correlate the sequence of anomalous activities following LNK execution, including PowerShell execution, persistence establishment, and external communications, to assess the overall threat level.

     

    4-2. Integrated Response Strategy Based on "Genian Insights E"

    This campaign is a multi-stage attack that begins with initial access through decoy documents assessed to have been created using generative AI and malicious LNK files, followed by obfuscated PowerShell execution, persistence through scheduled tasks, Git-based C2 communication, information collection, and subsequent RAT deployment.

    The following sequence of anomalous activities should be correlated and analyzed as a single attack context.

    • Execution of an LNK file contained in an archive
    • Execution of "cmd.exe" or PowerShell initiated by an LNK file
    • Abnormally long command-line arguments and custom Base64 decoding
    • Simultaneous display of a legitimate PDF and execution of malicious commands in the background
    • Creation of PowerShell scripts in the "AppData" or "Temp" path
    • Registration and periodic execution of hidden scheduled tasks
    • File transfers using GitHub Raw Content and the Contents API
    • Access to Git repositories using non-business accounts or personal access tokens (PATs)
    • Download of encrypted payloads disguised as image files

    "Genian Insights E" is an integrated endpoint security platform that correlates and analyzes various endpoint events, including process trees, command lines, file creation, scheduled tasks, and network connections.

    This enables the platform to visualize LNK execution, PowerShell activity, access to Git services, and subsequent payload execution as a single attack flow, even when each individual event may appear legitimate in isolation.

    Based on "LnkTarget" information, it can also identify the targets and commands referenced or executed by an LNK file from the initial stage and correlate them with subsequently created scripts, child processes, persistence activity, and external communications.

    This visibility provides a foundation for effectively responding to attacks that abuse legitimate cloud services and development platforms to evade detection.

    Ultimately, even if AI improves the quality of decoy documents and accelerates attack preparation, it cannot conceal the execution, persistence, communication, and payload-related activities that occur on the endpoint.

    Effective response to this campaign therefore requires organizations to continuously incorporate the latest indicators of compromise while establishing an EDR-centered integrated response framework capable of analyzing correlations across attack stages and rapidly blocking anomalous activity.

     

    [Figure 4-1] Malicious LNK File Detected by EDR

    [Figure 4-1] Malicious LNK File Detected by EDR

     

    Using the Attack Storyline feature in Genian Insights E, malicious LNK files created during archive extraction can be quickly detected.

    This enables malicious activity to be identified at the initial stage of compromise, supporting rapid response and preventing further spread.

     

    [Figure 4-2] Detection of PowerShell Commands Executed through an LNK File

    [Figure 4-2] Detection of PowerShell Commands Executed through an LNK File

    When the malicious LNK file is executed, a PowerShell process is launched as part of the execution chain, followed by a series of malicious activities, including additional command execution and payload downloads.

    EDR analyzes these process execution flows and behavior-based events in real time, enabling attack activity to be quickly identified and addressed.

     

    [Figure 4-3] GitHub C2 Access via PowerShell

    [Figure 4-3] GitHub C2 Access via PowerShell

    After the PowerShell command is executed, the malware communicates with the GitHub C2 server at regular intervals through scheduled tasks and other mechanisms to receive additional commands and perform malicious activities.

    Based on these recurring network communication patterns and process behavior data, EDR detects anomalous activity and helps security administrators quickly identify the threat and take appropriate response measures.

     

    [Figure 4-4] Genian Insights E Analysis View

    [Figure 4-4] Genian Insights E Analysis View

     

    Genian Insights E provides key information on detected threats through a dedicated Analysis view, allowing administrators to understand the attack flow and major activities at a glance.

    This enables administrators to quickly review detected threats and efficiently conduct detailed analysis and response actions.

     

     

    5. IoC (Indicator of Compromise)


    • MD5

    02ebc2356f9f700bbdac444cdefa0da2

    0d8ceb7dea7d471afa2f8e753b13d2d6

    1f378c0efc13669dada1fe340c6837bd

    2669731cb5ff664dfb5fbfc37637876d

    2ab3df4762fbde5d86e99a1ad147850e

    2e76d5316663a3dc472398b1c01cb9a8

    2eb77109cce1e8afca6245c2963e52a6

    302725413076d1aeaee2d7f2b3692646

    30792a0c0dfad55fb2b19d3e30e9a7d4

    30d5f17d5e3f85be18220a7cab0b9fff

    37cec428257cd41153cf43d7f1a12652

    3b9d40f3d620ec87960b4350d42ccc03

    3e2110d233d4543830e14c78d53900f4

    422a221851ea6ad15f53cd3aea51c8af

    49bdbe7e6cbb88842afcce3a9fe60e9b

    4d87fef16790cbe1df72007d99149665

    5577fffb5b5acd3771ef9dc696498f1e

    5af95590a33b9bc64d95808f1fc71b78

    5c5672bb14e1d2f07a8318ffec19b213

    6add815cd61d6514f81a23ab8c23405a

    73ff669fc282653bd6c42cf87ade9337

    7f12fa589f56f6203c692715b3958d30

    8406075af0a1e9ec09bafdc0de01f138

    8c859a03814443c6f0da341ee594c352

    a1c07ac866fb6b388e38c6bb1d4bbe94

    a343d8bcf02a0554fa271452a512f3ce

    a435292106026e257789036a70ee1a14

    a5701848f82c65a55765dc534111899f

    aa9d5dd632bb90addca480eaa5ff4382

    af3fa7f22f6e97901f20326cc12bdb49

    b406ea5b8628cb7801f47c0189b96182

    b50dad56d891ef230656b37ce62cdada

    b516ec6c6b37618ad65080a063270ea4

    ba0238423b5c29667cd760ccd7b000aa

    ba8e682a72c6a3e634c070f0fb057bf5

    bbf1b0ab9fc27439de4386ed7b8fc151

    c410055bfa198937825dfd7e41000e7a

    c63d021de798034cbf933e1c99bcb83f

    c7723bf166ef08ff3112257a1244f584

    ca0b57807f79f26e7f59cab2a2542da0

    e0e4aec6d494fe68cdaa52d6878a8366

    e22367800e9d39bc865bd50cddd0537d

    ead95793528572e7b89679860e2f2116

    ed2f8dd9b96d706d833b7aa545b8e621

    f4e7ca8c1de252840c1f0e957cd4b717

    f73e07efb8707e3561e9cbff74557acb

     

    • C2

    112.216.9[.]171

    170.205.29[.]83

    170.205.30[.]227

    185.27.134[.]140

    27.102.137[.]126

    27.102.137[.]159

    27.102.138[.]44

     

    • Domain

    stoks.great-site[.]net

     

    • Email

    apollo1030109@gmail[.]com

    awed33@outlook[.]kr

    belendong40@gmail[.]com

    brandonleeodd.93@gmail[.]com

    contrasde@outlook[.]kr

    devlion413@gmail[.]com

    eros1030109@gmail[.]com

    hera1030109@gmail[.]com

    holowin401@gmail[.]com

    holowin@gmail[.]com

    jecoma@outlook[.]kr

    johnstones19850308@gmail[.]com

    johnstones8888@outlook[.]com

    kkkkk79@outlook[.]kr

    tomas3015@outlook[.]kr

    trungvo5131993@gmail[.]com

    tttsssuuu@outlook[.]kr

    whitewolf20000312@gmail[.]com