#GitPower

Incident/Operation

2026-08-09 • AI를 공격 체계에 접목하는 김수키, 미끼 문서 제작부터 로컬 LLM 구축까지

Operation GitPower is a 2026 continuation of Kimsuky's FlowerPower activity targeting foreign diplomatic missions and people or organizations involved in policy, academia, international cooperation, military affairs, security research, finance, and virtual assets. Spear-phishing archives contain malicious shortcuts disguised as official or professional documents; heavily obfuscated commands launch hidden PowerShell, establish persistence through scheduled tasks, and retrieve encrypted AsyncRAT payloads from Git-based infrastructure. The campaign also shows operators using local large-language-model environments and generative AI to produce convincing decoys and support research workflows, while relying on existing models rather than training a proprietary system.

Tagged Reports

« Back