Kimsuky Uses AI Agent Opencode to Create Phishing Decoys
Kimsuky, a North Korean-linked hacking group, is using AI tools to create fake emails and messages that look like they come from real South Korean companies. These tricks trick users into opening malicious files that can steal data or install spyware.
- Report priority
- Medium
How it works
- Kimsuky sends fake emails and messages that look like they come from real South Korean companies.
- The messages trick users into opening a file with a.lnk extension, which is a shortcut file that can secretly run harmful programs when opened.
- The AI tool helps the attackers make these fake messages look more real, increasing the chance that someone will open the file and get infected.
What to do
If you are a South Korean user who gets unexpected emails or messages asking you to open files with a.lnk extension, be careful. These files can secretly install spyware on your computer. Do not open any suspicious files, even if they look like they come from a trusted source.
Do not open any unexpected files, especially those with.lnk extensions. If you accidentally opened one, scan your computer with updated antivirus software and check for unusual activity. If you suspect your data was stolen, contact South Korean cybersecurity authorities or your bank immediately.
Technical details
An AI-generated email appears to come from a well-known South Korean bank, asking the user to open a 'security update' file. When the user clicks the file, it secretly installs spyware that steals login details and emails.
Threat analysts reveal Kimsuky uses AI agent opencode to mass-produce phishing decoys. Discover how the group leverages AI to enhance its LNK attacks.