← Back to feed
AI SecurityEmerging1 sourceSep 6, 2026 · 12:05via Malware.news

Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve

Brief

◈ Key Findings

  • Evidence of follow-on distribution using malicious LNK files contained in ZIP archives identified in Kimsuky-linked attack activity
  • Traces of the AI agent "opencode" identified in decoy PDF metadata, showing the continued use of AI and LLMs to mass-produce decoys
  • All LNK files configured to launch PowerShell, with encrypted loaders concealed within lengthy execution arguments
  • Decoy documents and follow-on PowerShell commands retrieved from GitHub Raw Content paths using a GitHub PAT
  • Anti-analysis logic designed to detect analysis tools and virtualization processes and terminate execution when specific conditions are met
  • Need to strengthen EDR-based detection and threat hunting for the abuse of LNK files, PowerShell, and GitHub

Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve

Read more on Malware.news