Kimsuky Group Leverages AI in Operation GitPower Phishing Campaign

Kimsuky Group Leverages AI in Operation GitPower Phishing Campaign

First seen 10 Aug 2026, 13:04 UTC Cybersecuritynewswww.genians.co.kr 75% similarity 75.5

Article Content

Browse articles
ThreatCluster

The Kimsuky cyber threat group, linked to North Korea, is executing a campaign known as Operation GitPower, which utilizes AI-generated documents to enhance traditional phishing tactics. This operation involves the distribution of ZIP archives containing malicious Windows shortcut files that lead to the deployment of AsyncRAT, a remote-access trojan. The campaign builds on previous tactics seen in the FlowerPower operation and employs a Git-based command-and-control structure. Recent attacks have targeted professionals in policy, academia, and security research, using documents that appear credible and are crafted with generative AI. The Kimsuky group has been known for spear phishing attacks for years, and this latest iteration demonstrates their adaptation of AI technologies to increase the effectiveness of their attacks. Security teams are advised to monitor for unusual execution patterns in LNK files and to be cautious of documents related to finance and virtual assets. The threat landscape remains active as Genians Security Center continues to track these developments.

Key Points: • Kimsuky is using AI-generated documents in phishing attacks to deliver AsyncRAT. • Operation GitPower combines traditional phishing methods with AI for enhanced credibility. • Security teams should monitor for unusual execution patterns in LNK files.

ThreatCluster AI How this analysis works

Timeline

2023-01-01
FlowerPower campaign disclosed
Kimsuky was identified using PowerShell-based frameworks and Git repositories for attacks.
Genians Security Center
2024-01-01
Hacking campaign disguised as New Year column reported
Kimsuky employed tactics similar to those observed in the FlowerPower campaign.
Genians Security Center
2026-08-10
Operation GitPower identified
Kimsuky is actively using AI-generated documents in phishing attacks targeting professionals.
Cybersecuritynews

Community

Browse all →