Tech & Science

North Korean Hackers Target Devices with PowerShell Trick in Evolving Cyberattack

44
Hack Warning Cyberattack

A North Korea-linked hacking group, Kimsuky, has adopted a new tactic in cyberattacks, using PowerShell to hijack devices.

This technique is a departure from their usual methods and leverages social engineering to trick victims into running malicious PowerShell commands.

How the Attack Works:

The attacker masquerades as a South Korean government official and builds rapport with the target. Then, they send a spear-phishing email containing a malicious PDF attachment.

Inside the document, the victim is urged to click a URL that directs them to a list of steps to register their Windows system.

This registration link asks the victim to run PowerShell as an administrator and paste a malicious code snippet into the terminal.

Impact of the Exploit:

If executed, the code downloads a browser-based remote desktop tool and a certificate file with a hardcoded PIN from a remote server.

This allows the attacker to register the victim’s device, gaining access to it for data exfiltration.

This spear-phishing method enables the hackers to bypass security protections, relying on the victim to infect their own system.

This tactic aligns with the growing trend of attacks where the target unknowingly aids in compromising their own device, making it harder to detect and prevent.

Microsoft has reported these attacks starting in January 2025, although similar strategies have been used by other threat actors, including those behind the Contagious Interview campaign.

This incident underscores the evolving tactics of cybercriminals and highlights the need for greater vigilance, particularly when receiving suspicious emails.

Written by
Sazid Kabir

I've loved music and writing all my life. That's why I started this blog. In my spare time, I make music and run this blog for fellow music fans.

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Stay updated with nomusica.com. Add us to your preferred sources to see our latest updates first.

Related Articles

Jeff Bezos (Amazon CEO)
Tech & Science

Jeff Bezos Enters Satellite Internet Race With Starlink Rival TeraWave

Jeff Bezos’ space company, Blue Origin, has announced a new satellite internet...

Google Gradient Logo
Finance & BusinessTech & Science

Google Returns $350 Billion to Shareholders Over 10 Years

Over the past decade, Alphabet Inc. (GOOGL), the parent company of Google,...

OnePlus Ace 5 Series
SmartphonesTech & Science

OPPO Denies OnePlus Shutdown Amid Rumors of Brand Cutbacks

Recent reports claiming OnePlus phones are “no more” have stirred concern among...

Inhaler for Asthma Patients
Tech & ScienceHealth & Foods

Blood Test Predicts Severe Asthma Attacks Years in Advance

Researchers at Mass General Brigham and the Karolinska Institutet have developed a...