cognitive cybersecurity intelligence

News and Analysis

Search

Kimsuky Uses Local LLMs, AI-Generated Lures and GitHub C2 to Deploy AsyncRAT

Kimsuky Uses Local LLMs, AI-Generated Lures and GitHub C2 to Deploy AsyncRAT

Kimsuky has been observed blending polished AI-made documents with familiar phishing tactics to push AsyncRAT, a remote-access trojan.

The campaign shows how old delivery methods can gain new credibility when the bait looks professionally written and carefully formatted.

The activity, tracked as Operation GitPower, begins with ZIP archives carrying Windows shortcut files that appear to be ordinary documents.

Opening one can launch concealed PowerShell code while a harmless-looking PDF opens on screen, reducing the chance that a target notices the compromise.

Genians analysts identified the campaign after tracking infrastructure tied to GitHub- and GitLab-based activity.

Genians said in a report shared with Cyber Security News (CSN) that the targets include diplomatic missions and military, security, virtual-asset, policy, and academic organizations.

AI-Enabled Attack Flow (Source – Genians)

The operational impact is wider than a single malicious file. Attackers can update scripts and payloads in public code repositories, use trusted web traffic to blend in, collect system details, and keep access through scheduled tasks.

That makes early behavioral detection especially important, as a recent North Korean GitHub C2 campaign also illustrated.

Kimsuky Uses Local LLMs, AI-Generated Lures and GitHub C2

The operators set up local language-model environments using Ollama, GPT4All, and Msty.

Evidence also included a GPT4All LocalDocs database, suggesting that documents held by the group could be searched and used as an AI knowledge base.

The researchers did not find evidence that the group trained its own models.

Examples of Spear Phishing Emails (Source – Genians)

Instead, the traces suggest a research and integration phase: testing locally run AI, document retrieval, automation frameworks, and speech-to-text tools that could help process stolen material or support future malware development.

At the front of the intrusion, AI-generated decoys covered investment, virtual-asset, and game-development themes.

Their polished language and consistent design can make the usual warning signs less reliable.

Readers following AI-assisted phishing campaigns have seen the same broader problem: convincing content is no longer a useful safety test by itself.

The shortcut loader hid a roughly 3,800-character PowerShell command, including a long run of spaces designed to obscure the important portion in Windows properties.

It retrieved a decoy PDF through GitHub Raw Content, then created scripts in temporary and AppData locations and registered a hidden recurring task.

Examples of PDF Decoy Documents (Source – Genians)

GitHub served as more than a download point. The scripts fetched follow-on files and collected operating-system, hardware, boot-history, process, and network information.

The collected data could then help operators decide how to continue the intrusion while normal GitHub access made the traffic less conspicuous.

AsyncRAT Delivery and Defense

Public repositories held files named apple.png, fox.png, lion.png, rabbit.png, and wolf.png, but the files were encrypted .NET AsyncRAT payloads rather than images.

This disguise echoes other AsyncRAT delivery techniques, where a legitimate-looking artifact hides a tool that can give attackers remote control of a compromised Windows system.

The report linked apple.png and rabbit.png with rTom.exe_r, while other image-named payloads used a hard-coded command-and-control address.

LNK File Command-Line Arguments (Source – Genians)

The campaign also used string splitting, custom Base64 decoding, and altered file headers, small evasions that together complicate simple signature checks.

Organizations should treat a ZIP-delivered LNK file launching cmd.exe or PowerShell as a high-priority signal, especially when it carries unusually long arguments.

Detection teams should correlate that event with hidden PowerShell, new scripts in Temp or AppData, scheduled-task creation, GitHub Raw Content or Contents API traffic, non-business personal-access tokens, and image files that behave like encrypted executables.

The practical lesson is to look at the sequence, not merely the lure. Block or investigate suspicious shortcut files before execution, restrict unnecessary script execution, and hunt for the combined behavior across endpoints and network logs.

This approach also helps counter the latest AsyncRAT cloud abuse, where trusted services can mask a multi-stage infection chain.

AI may make phishing material faster to produce and harder to spot, but it does not remove the actions required to run malware, maintain access, and contact an operator.

Defenders that join those events together can identify the campaign even when each individual action initially appears ordinary.

Indicators of compromise (IoCs):-

TypeIndicatorDescriptionC2 IP address112.216.9[.]171AsyncRAT command-and-control address embedded in fox.png, leopard.png, lion.png, and wolf.pngIP address169.254.33[.]137Address observed during testing alongside rTom.exe_r and AsyncRAT payloadsIP address170.205.29[.]83Published IoCIP address170.205.30[.]227Published IoCIP address185.27.134[.]140Published IoCIP address27.102.137[.]126Published IoCIP address27.102.137[.]159Published IoCIP address27.102.138[.]44Published IoCDomaintoks.great-site[.]netPublished IoCEmail addressapollo1030109@gmail[.]com; awed33@outlook[.]kr; belendong40@gmail[.]com; brandonleeodd.93@gmail[.]com; contrasde@outlook[.]kr; devlion413@gmail[.]comPublished IoCsEmail addresseros1030109@gmail[.]com; hera1030109@gmail[.]com; holowin401@gmail[.]com; holowin@gmail[.]com; jecoma@outlook[.]kr; johnstones19850308@gmail[.]comPublished IoCsEmail addressjohnstones8888@outlook[.]com; kkkkk79@outlook[.]kr; tomas3015@outlook[.]kr; trungvo5131993@gmail[.]com; tttsssuuu@outlook[.]kr; whitewolf20000312@gmail[.]comPublished IoCsFile nameapple.png; fox.png; leopard.png; lion.png; rabbit.png; wolf.pngRC4-encrypted .NET AsyncRAT payloads disguised as image filesFile namerTom.exe_rFile stored alongside AsyncRAT payloadsFile namepoqpwoqwdjoweij.ps1; irujkdnjhgttrhdkfdu.ps1; lpieuysjfgtrja.ps1; ms_update.ps1PowerShell scripts used in the infection chainFile nameriudxkfngidruhkr.pdf; priujghtjytfcghffgt.txt; bhjfjkfgrtwehjbfgcf.txtFiles retrieved through GitHub infrastructureScheduled taskZHUYHJGTYTFSUHIPOKLKHJHUYGVHGNFHHidden recurring task used for persistenceMD5502ebc2356f9f700bbdac444cdefa0da; 20d8ceb7dea7d471afa2f8e753b13d2d; 61f378c0efc13669dada1fe340c6837b; d2669731cb5ff664dfb5fbfc37637876Published malware hashesMD5d2ab3df4762fbde5d86e99a1ad147850; e2e76d5316663a3dc472398b1c01cb9a; 82eb77109cce1e8afca6245c2963e52a; 6302725413076d1aeaee2d7f2b369264Published malware hashesMD5630792a0c0dfad55fb2b19d3e30e9a7d; 430d5f17d5e3f85be18220a7cab0b9ff; f37cec428257cd41153cf43d7f1a1265; 23b9d40f3d620ec87960b4350d42ccc0Published malware hashesMD533e2110d233d4543830e14c78d53900f; 4422a221851ea6ad15f53cd3aea51c8a; f49bdbe7e6cbb88842afcce3a9fe60e9; b4d87fef16790cbe1df72007d9914966Published malware hashesMD555577fffb5b5acd3771ef9dc696498f1; e5af95590a33b9bc64d95808f1fc71b; 785c5672bb14e1d2f07a8318ffec19b; 2136add815cd61d6514f81a23ab8c23Published malware hashesMD5405a73ff669fc282653bd6c42cf87ade; 93377f12fa589f56f6203c692715b395; 8d308406075af0a1e9ec09bafdc0de01; f1388c859a03814443c6f0da341ee594Published malware hashesMD5c352a1c07ac866fb6b388e38c6bb1d4; bbe94a343d8bcf02a0554fa271452a51; 2f3cea435292106026e257789036a70e; e1a14a5701848f82c65a55765dc53411Published malware hashesMD51899faa9d5dd632bb90addca480eaa5; ff4382af3fa7f22f6e97901f20326cc; 12bdb49b406ea5b8628cb7801f47c018; 9b96182b50dad56d891ef230656b37cePublished malware hashesMD562cdadab516ec6c6b37618ad65080a06; 3270ea4ba0238423b5c29667cd760ccd; 7b000aaba8e682a72c6a3e634c070f0; fb057bf5bbf1b0ab9fc27439de4386edPublished malware hashesMD57b8fc151c410055bfa198937825dfd7e; 41000e7ac63d021de798034cbf933e1; c99bcb83fc7723bf166ef08ff3112257; a1244f584ca0b57807f79f26e7f59Published malware hashes

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
The post Kimsuky Uses Local LLMs, AI-Generated Lures and GitHub C2 to Deploy AsyncRAT appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts