Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
China-linked Hackers Use AI Agents to Attack Taiwan Government Websites
August 12, 2026
Critical Adobe ColdFusion flaws let attackers run arbitrary code
August 12, 2026
Google Chrome 115 Patches Five High-Severity Use-After-Free Flaws
August 12, 2026
Home/Threats/Kimsuky Hackers Target Recruiters, Crypto, Defense with LNK/JSE Lures
Threats

Kimsuky Hackers Target Recruiters, Crypto, Defense with LNK/JSE Lures

Key Takeaways The North Korea-backed Kimsuky group launched four distinct spear-phishing campaigns in the first half of 2025. Targets included corporate recruiters, cryptocurrency investors, defense...

Marcus Rodriguez
Marcus Rodriguez
May 19, 2026 5 Min Read
74 0

Key Takeaways

  • The North Korea-backed Kimsuky group launched four distinct spear-phishing campaigns in the first half of 2025.
  • Targets included corporate recruiters, cryptocurrency investors, defense personnel, and graduate school staff.
  • The attacks utilized LNK and JSE files as initial infection vectors, often disguised as legitimate documents.
  • Kimsuky demonstrated advanced evasion techniques, including rapid defense disabling and the abuse of trusted services like GitHub and Microsoft CDN for command-and-control.

North Korean Kimsuky Group Expands Cyber Espionage with Sophisticated LNK/JSE Lures

The Kimsuky advanced persistent threat (APT) group, widely recognized for its ties to the Democratic People’s Republic of Korea (DPRK), significantly expanded its cyber espionage activities in the first half of 2025. The group initiated four distinct spear-phishing campaigns, broadening its scope to include corporate recruiters, cryptocurrency enthusiasts, and defense sector personnel.

Table Of Content

  • Key Takeaways
  • North Korean Kimsuky Group Expands Cyber Espionage with Sophisticated LNK/JSE Lures
  • Diverse Lures for Specific Targets
  • Advanced Evasion and Legitimate Service Abuse
  • Kimsuky’s Initial Access Methods: LNK and JSE Files
  • Abuse of Legitimate Services for Command and Control
  • What You Should Do

Each campaign employed unique thematic lures but adhered to a consistent operational model: entice targets to open a malicious file, surreptitiously compromise their systems, and establish covert control. A detailed report from LogPresso analysts, shared with HackersRadar, outlines the group’s evolving tactics and infrastructure.

Diverse Lures for Specific Targets

The Kimsuky group meticulously crafted its lures to appeal to its varied targets. Recruiters were targeted with fake resumes and professional business cards, while cryptocurrency users received content related to Solana meme coins. Defense officials were sent documents seemingly pertaining to the K-ICTC International Scientific Combat Management Competition. Additionally, graduate school staff were tricked with what appeared to be enrollment documents. The overarching objective in each scenario was to gain an initial foothold without triggering immediate suspicion.

Campaigns (Source - LogPresso)
Campaigns (Source – LogPresso)

LogPresso’s analysis revealed a consistent attack flow across all four campaigns. This typically involved presenting a benign decoy document to the victim while simultaneously deploying a malicious payload in the background. Following this, the attackers established persistence on the compromised system and then set up a remote command-and-control (C2) channel. The primary differentiators between campaigns were the lure topics, initial access methods, and the specific C2 infrastructure utilized.

Advanced Evasion and Legitimate Service Abuse

Kimsuky demonstrated notable sophistication in its attacks, particularly in evading detection. Instead of relying on easily identifiable malicious servers, the group routed its C2 communications through legitimate and widely trusted platforms such as GitHub raw APIs, Microsoft Content Delivery Network (CDN), and VSCode tunnels. This strategy allowed their malicious traffic to blend seamlessly with normal network activity, making it exceptionally difficult for traditional, reputation-based security tools to detect.

Furthermore, the threat actors employed personalized target tracking, assigning unique IDs to victims and monitoring them through their IP and MAC addresses. This level of granular tracking suggests a highly organized and persistent espionage effort.

A critical finding across all four campaigns was the aggressive and immediate focus on defense evasion. Within five minutes of a victim opening the initial lure file, the malware initiated a series of actions to disable Windows User Account Control (UAC), register exceptions within Windows Defender, and embed itself into the Task Scheduler for persistent access across system reboots. This rapid execution highlights the need for advanced, behavior-based detection mechanisms rather than reliance on static indicators of compromise (IoCs).

Kimsuky’s Initial Access Methods: LNK and JSE Files

Three of the four identified campaigns leveraged LNK files, disguised as PDF documents, as their primary infection vector. Upon execution, these LNK files initiated a dual process: displaying a convincing decoy PDF to the user while covertly dropping a secondary LNK file into the Windows startup folder. This secondary file ensured persistence, subsequently downloading and executing PowerShell scripts from the attacker’s C2 server. This entire process was engineered to conclude in under five minutes, minimizing the window for human intervention or detection.

The fourth campaign adopted a different approach, utilizing a JSE (JScript Encoded) file with a deceptive double extension, appearing as “.hwpx.jse”. Due to Windows’ default behavior of hiding known file extensions, victims would perceive it as a legitimate Korean HWP document. Once opened, the JSE script employed the native Windows utility certutil to decode a hidden DLL, which was then loaded using rundll32.exe, another legitimate Windows component. This particular campaign further established persistent remote access via a VSCode tunnel, effectively leveraging Microsoft’s signed binaries to maintain stealth.

Abuse of Legitimate Services for Command and Control

A consistent pattern across all Kimsuky campaigns was the extensive abuse of legitimate online services for command and control (C2) operations. GitHub repositories served as hosts for malicious payloads and data exfiltration points. Microsoft CDN was exploited to deliver files without raising network alerts, while VSCode tunnels, authenticated via GitHub OAuth, facilitated persistent remote access. In certain instances, private servers such as nelark.icu acted as C2 infrastructure, and another campaign routed exfiltrated data through the Korean website yespp.co.kr.

LogPresso’s analysis underscores that relying solely on blocking specific domains or file hashes is insufficient against such an adaptable threat actor. Given Kimsuky’s propensity for rapidly rotating its infrastructure, organizations must prioritize behavior-based detection strategies that cover the entire attack chain. This includes monitoring for suspicious LNK or JSE files with double extensions, unexpected Task Scheduler entries masquerading as legitimate services (e.g., OneDrive or Intel), and any unauthorized disabling of Windows UAC.

What You Should Do

  • Enable Hidden File Extensions: Configure Windows to always show file extensions to help identify deceptive double extensions (e.g., .pdf.lnk or .hwpx.jse).
  • Implement Advanced Endpoint Detection and Response (EDR): Utilize EDR solutions capable of behavior-based detection to identify suspicious process chains, even when legitimate tools are abused.
  • Monitor Task Scheduler Entries: Regularly audit Task Scheduler for newly created or modified tasks, especially those disguised as system utilities or common applications (e.g., OneDrive, Intel services).
  • Strengthen Email Security: Deploy robust email security gateways with advanced threat protection to detect and block spear-phishing attempts containing malicious attachments.
  • User Awareness Training: Conduct frequent training for employees on identifying phishing emails, especially those with unusual attachments or links, and emphasize caution with files from unknown senders.
  • Monitor UAC Changes: Alert on and investigate any attempts to disable or modify User Account Control (UAC) settings outside of authorized administrative activities.
  • Network Traffic Analysis: Monitor network traffic for unusual connections to legitimate services (GitHub, Microsoft CDN) that might indicate C2 activity or data exfiltration.

Indicators of Compromise (IoCs):-

Type Indicator Description
File Hash (MD5) 80088af673b0117dbd5cf528021dd970 1.pdf.lnk (Campaign 1) 
File Hash (MD5) c499e415f7e07f513d8319013a8b2e86 1.pdf.lnk.zip (Campaign 1) 
File Hash (MD5) 0331a83b58231cb0cd3bfe319003ed1a OneDrive.lnk (Campaign 1) <a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/f6dec54e-b0a1-467c-a79c-a49cb4533626/Kimsuky-Hackers-Use-LNK-and-JSE-Lures-to-Target-Recruiters-Crypto-Users-and-Defense-Officials.pdf?AWSAccessKeyId=ASIA2F3EMEYETMWYCGIO&Signature=aVBc5XbatjYzVeuNSrlQJCsyrOs%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEBEaCXVzLWVhc3QtMSJHMEUCIQDBRbEQalcpKKtpfbEHtfLvqUGyKb9%2FihRyCzkR31XLKwIgT4nkgZI0M8gSbcR%2BmizC1dHww5d8m4Vzr1L35hCe3qkq%2FAQI2v%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDDJGWPSTHcyPJPBFkyrQBGWM3T7ozURBf5N0J%2B8TGvlH03aYia2R9RG%2BWB8vdCku147KRUMLz8BmcQlEPmbbJj6k%2BfwdScajhE7VaQZxnI9m9eXKcdY%2FNCB%2BLYbF97dakXJUv%2B2RGne46jd6wWABoyyb%2BC%2B%2BLnYh9z%2FGOTJk0fJd%2FyDqYEL9Qb2ZgOkb7vITxaltK3qD4zb3u12O%2FX%2BShraCo6Yqz9z8rv3Mx88WcbTlQPjLGOjfQJ%2B6%2Bx4AC%2BUvKrC3hmrBYXNMsny0BTmngH4sY0Fk71Te0LSVZKyI0

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwarephishingSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Elite SOCs Operationalize Threat Intelligence with These 3 Tactics

Next Post

Gentlemen Ransomware Targets Windows, Linux, NAS, BSD, and ESXi Systems

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical VMware vCenter flaw exploited for remote access
August 12, 2026
2.86 Billion Credentials Compromised, Enterprise Access for Sale
August 12, 2026
Fake Chrome VPN Extensions Hijack Traffic via SOCKS5 Proxies
August 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us