The PolySwarm Blog

Analyze suspicious files and URLs, at scale, millions of times per day. Get real-time threat intel from a crowdsourced network of security experts and antivirus companies competing to protect you.

Kimsuky Expands AI Capabilities Through a Local AI Development Environment in Operation GitPower

Aug 17, 2026, 2:34:51 PM / by The Hivemind posted in Threat Bulletin, Kimsuky, PowerShell malware, AI-enabled cyber attacks, malicious LNK files, Operation GitPower, North Korea APT, GitHub C2

0 Comments

Verticals Targeted: Policy Organizations, Academia, International Cooperation Organizations, Diplomatic Missions, Military, Security, Security Research, Virtual Assets
Regions Targeted: South Korea
Related Threat Actors: Kimsuky

Executive Summary

Researchers identified a continuation of the North Korean Kimsuky cyber espionage campaign, designated Operation GitPower, which combines established spear-phishing techniques with emerging artificial intelligence capabilities. While the campaign continues to rely on malicious LNK files, PowerShell loaders, and GitHub-hosted C2 infrastructure, investigators also uncovered evidence that the threat actor has deployed local large language model (LLM) environments, retrieval-augmented generation (RAG), AI development frameworks, and speech-to-text tools. The findings suggest Kimsuky is systematically building AI-enabled operational capabilities to support future espionage activities rather than merely experimenting with generative AI.

Read More

Velvet Chollima Using Gomir Linux Backdoor

May 24, 2024, 11:58:05 AM / by The Hivemind posted in Threat Bulletin, Espionage, North Korea, Linux, Kimsuky, GoBear, Velvet Chollima, Gomir, Troll Stealer

0 Comments

Related Families: GoBear, Troll Stealer, BetaSeed, Endor
Verticals Targeted: Government 

Executive Summary

North Korea nexus threat actor group Velvet Chollima was observed using a new Linux backdoor, dubbed Gomir, to target entities in South Korea.

Read More

Kimsuky GoldDragon C2 Cluster

Sep 19, 2022, 2:06:44 PM / by PolySwarm Tech Team posted in Threat Bulletin, Espionage, North Korea, Kimsuky, GoldDragon

0 Comments

Verticals Targeted: Think Tanks, Media, Government

Executive Summary

In early 2022, the North Korean threat actor group Kimsuky targeted a South Korean think tank and media entities. In this campaign, they leveraged what is known as the GoldDragon backdoor and associated C2 cluster.

Key Takeaways

Read More

Subscribe to Email Updates

Lists by Topic

see all

Posts by Topic

See all

Recent Posts