A newly uncovered phishing campaign is actively targeting organizations in South Korea by abusing GitHub as a Command and Control (C2) server.
Discovered by FortiGuard Labs, the attacks rely on heavily obfuscated malicious LNK (shortcut) files to infiltrate systems. While these files have circulated since early 2024, recent variants show a significant increase in stealth and sophistication.
Evolving Infection Chain and Evasion Tactics
The infection process is a carefully orchestrated multi-stage attack designed to remain invisible to victims and security software.
In older versions of this campaign, which were known to spread the XenoRAT malware, threat actors used simple character concatenation to hide their GitHub C2 addresses.
However, recent iterations have drastically evolved. The attackers now embed decoding functions directly within the LNK file arguments and have stripped away identifiable metadata to avoid detection.
When a victim opens the malicious LNK file, it immediately drops a decoy PDF document related to their business.

This creates the illusion of normal activity, leading the victim to believe the file is safe. While the user reads the decoy, a hidden PowerShell script executes silently in the background.
Abusing Trusted Infrastructure For Command and Control
The most notable aspect of this campaign is its strategic abuse of legitimate public infrastructure.
Rather than relying on custom, easily flagged malicious servers, the attackers use the GitHub API as their primary C2 channel.
The harvested system data is uploaded directly to private GitHub repositories using hardcoded access tokens.

Researchers identified multiple GitHub accounts involved in this operation, with one account named “motoralis” acting as the central operational hub.
The attackers maintain a network of both active and dormant accounts to ensure immediate redundancy if one is taken down.

By conducting all data exfiltration and payload hosting within private repositories, the threat actors keep their malicious activities hidden from public view while riding on the high reputation of the GitHub domain.
According to Fortinet research, the malware uses a continuous “keep-alive” script to maintain a persistent connection with the GitHub C2.
This script routinely gathers network configuration details and uploads them to the repository, allowing attackers to monitor the victim’s network status in real time and fetch additional malicious modules as needed.
This campaign highlights a growing trend where threat actors minimize the use of custom malware in favor of “Living off the Land” (LOLBins) using native Windows tools like PowerShell and VBScript to carry out attacks.
Because GitHub is widely trusted and frequently allowed in corporate environments, this combination of native tools and abused web services creates a highly stealthy infection chain.
Organizations are advised to monitor for unusual PowerShell activity and remain vigilant against unexpected shortcut files to defend against this evolving threat.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.