DPRK Hackers Use GitHub and Korean Docs for Persistent Espionage
DPRK-linked threat actors are combining region-specific document exploitation with commodity platforms to maintain stealthy, persistent access in South Korea. They use LNK phishing to deliver decoy documents in the Korean HWP format, which leverages OLE and DLL side-loading to increase social engineering success and evade detection. The attackers employ GitHub repositories as command-and-control (C2) infrastructure, blending malicious callbacks into legitimate traffic to avoid easy takedown and detection. This approach enables persistent footholds that survive reboots and can push remote access tools like RokRAT. Standard defenses focusing on patching or blocking known malicious domains miss this threat because GitHub traffic appears legitimate, LNK files with decoys bypass casual suspicion, and persistence mechanisms evade simple file-based detection. This campaign raises the espionage risk for organizations handling Korean-specific documents or with strategic ties to South Korea, and