www.genians.co.kr
Kimsuky Group Leverages AI in Operation GitPower Phishing Campaign
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Kimsuky cyber threat group, linked to North Korea, is executing a campaign known as Operation GitPower, which utilizes AI-generated documents to enhance traditional phishing tactics. This operation involves the distribution of ZIP archives containing malicious Windows shortcut files that lead to the deployment of AsyncRAT, a remote-access trojan. The campaign builds on previous tactics seen in the FlowerPower operation and employs a Git-based command-and-control structure. Recent attacks have targeted professionals in policy, academia, and security research, using documents that appear credible and are crafted with generative AI. The Kimsuky group has been known for spear phishing attacks for years, and this latest iteration demonstrates their adaptation of AI technologies to increase the effectiveness of their attacks. Security teams are advised to monitor for unusual execution patterns in LNK files and to be cautious of documents related to finance and virtual assets. The threat landscape remains active as Genians Security Center continues to track these developments.
Key Points: • Kimsuky is using AI-generated documents in phishing attacks to deliver AsyncRAT. • Operation GitPower combines traditional phishing methods with AI for enhanced credibility. • Security teams should monitor for unusual execution patterns in LNK files.