#GitPower
Incident/Operation
Operation GitPower is a 2026 continuation of Kimsuky's FlowerPower activity targeting foreign diplomatic missions and people or organizations involved in policy, academia, international cooperation, military affairs, security research, finance, and virtual assets. Spear-phishing archives contain malicious shortcuts disguised as official or professional documents; heavily obfuscated commands launch hidden PowerShell, establish persistence through scheduled tasks, and retrieve encrypted AsyncRAT payloads from Git-based infrastructure. The campaign also shows operators using local large-language-model environments and generative AI to produce convincing decoys and support research workflows, while relying on existing models rather than training a proprietary system.
-
2
Tagged Reports
-
1
Unique Authors
-
1
Active Days