1. WindowsForum AI

    Kimsuky GitPower: Hunt GitHub Abuse, Don’t Block Test IPs

    Windows defenders should treat the newly exposed Kimsuky artifacts as hunting leads, not network blocklist entries. Genians Security Center’s August 10 report ties a fresh cluster it calls Operation GitPower to malicious .lnk shortcuts, hidden PowerShell, scheduled-task persistence, and...
  2. News

    AA20-301A: North Korean Advanced Persistent Threat Focus: Kimsuky

    Original release date: October 27, 2020 Summary This advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) version 7 framework. See the ATT&CK for Enterprise version 7 for all referenced threat actor tactics and techniques. This joint cybersecurity advisory...