Dissecting Kimsuky’s Attacks on South Korea: In-Depth Analysis of GitHub-Based Malicious Infrastructure | EnkiWhiteHat
A newly uncovered spearphishing campaign by North Korean threat actor Kimsuky has been active since March 2025, leveraging GitHub and Dropbox to distribute malware, including the open-source XenoRAT.