securityonline.info 10 Sept 2026, 06:35 UTC

Kimsuky Uses AI Agent to Scale Phishing Against Finance Teams

Kimsuky Uses AI Agent to Scale Phishing Against Finance Teams
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor

NORTH Korean state-sponsored threat group Kimsuky is alleged to be using an AI-powered agent, named opencode, to automate the creation of phishing decoys and scale its espionage campaigns. Researchers from Genians Security Center report intercepting 13 malicious LNK files in August 2026 that masqueraded as financial documents, insurance records, and certificate renewals.

Deep analysis of document metadata linked these lures to opencode, with decoy PDFs showing AI-generated content and placeholders that were not replaced before distribution. The attacker chain starts when a user opens a ZIP Archive containing the disguised LNK, which launches a hidden PowerShell script. The script then fetches payloads from GitHub using hardcoded Personal Access Tokens and, if GitHub is blocked, relies on Pastebin as a secondary command channel to maintain persistence.

Analysts attribute the activity to Kimsuky with high confidence, tying it to the group’s ongoing Operation GitPower and noting distinctive fingerprints, such as exactly 300 leading spaces in LNK properties and a custom arithmetic substitution decoder used to decrypt payloads. The campaign marks a shift in targets from diplomats and academics to retail operators and corporate financial departments, enabled by AI to mass-produce decoys and coordinate multiple simultaneous campaigns.

The campaign also exhibits anti-analysis behaviour; the malware searches for virtual machines and commonly used sandbox tools before execution. Defence guidance emphasises behavioural detection, monitoring for abnormal PowerShell activity spawned by LNKs, and unusual outbound connections to raw.githubusercontent[.]com and Pastebin using API authentication headers.

View full article

Article by CyberSIXT