A sophisticated new phishing campaign is targeting organizations in South Korea by using malicious Windows shortcut (LNK) files and exploiting GitHub as a covert Command and Control (C2) network.
Discovered by FortiGuard Labs, these ongoing attacks leverage a multi-stage execution process designed to deploy malware while evading traditional security detection.
Researchers believe this activity is linked to North Korean state-sponsored threat actors, who frequently use these tactics to expand their surveillance and espionage operations.
Evolution Of The LNK Infection Chain
The attack begins when a target interacts with a malicious LNK file. In older variants, attackers used basic character concatenation to hide their GitHub C2 addresses and access tokens.
Investigators also found metadata, such as the “Hangul Document” naming convention, that strongly linked the activity to known North Korean groups, including Kimsuky, APT37, and Lazarus.
However, the latest attacks completely remove this identifiable metadata. Instead, the LNK file contains a decoding function hidden within its arguments.
When clicked, this function decodes and drops a decoy PDF document to fool the victim into believing the file opened normally. Simultaneously, a malicious PowerShell script executes silently in the background.
The most notable aspect of this campaign is its abuse of legitimate public infrastructure. Instead of setting up suspicious external servers, the attackers upload the stolen system logs to specific private GitHub repositories using hardcoded access tokens.
Because GitHub is a highly trusted platform that is frequently allowed in corporate network environments, this malicious data exfiltration easily blends in with normal, encrypted web traffic.

Through their investigation, FortiGuard Labs uncovered an extensive C2 network operated by the attackers on GitHub.
The primary account serves as the operational hub. In contrast, several other accounts remain dormant to provide immediate backup if the primary repositories are taken down.
By conducting all malicious activity within private repositories, the threat actors successfully hide their payloads from public view.

To maintain this persistent connection, the malware uses a final “keep-alive” script. This script continuously checks the target’s network configuration and uploads the data to GitHub.
It also allows the attackers to fetch additional modules or issue new commands directly from their repositories, giving them total control over the compromised environment.

According to Fortinet research, this campaign highlights a growing trend where threat actors abuse trusted web services and built-in Windows features to bypass corporate security defenses.
By using native applications for deployment and evasion, attackers can successfully launch campaigns with notably lower detection rates.
Security platforms currently track this specific threat under the identifier LNK/Agent.ALN!tr. To defend against this sophisticated infection chain, organizations are urged to remain cautious of untrusted shortcut files and implement robust anti-phishing training.
Furthermore, IT teams must actively monitor for unusual PowerShell or VBScript execution within their networks to detect and prevent similar covert intrusions.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.