A sophisticated state‑sponsored espionage campaign has been targeting foreign embassies in Seoul, deploying the remote access trojan XenoRAT via malicious GitHub repositories, researchers reveal.

According to Trellix, the campaign — which began in March and continues to this date — has featured at least 19 spear‑phishing attacks directed at high‑value diplomatic targets. Although the infrastructure and tactics closely resemble those employed by North Korea’s Kimsuky (APT43), certain behavioral patterns suggest possible Chinese sponsorship or involvement.

A Multi-Stage Phishing Offensive

The adversaries orchestrated the operation in three distinct phases between early March and July. The initial probing phase, starting in March, targeted a Central European embassy. By May, the campaign shifted focus toward diplomatic entities, employing more elaborate phishing lures.

A particularly telling example occurred on May 13, 2025, when attackers sent an email to a Western European embassy masquerading as a high-ranking EU delegation official, inviting the recipient to a “Political Advisory Meeting” on May 14.

From June through July, the messaging veered toward themes aligned with the U.S.‑Korea military alliance. Recipients comprised predominantly European embassies in Seoul — and the phishing content included fake meeting invites, official-looking letters, and event announcements sent under the guise of diplomats.

The phishing emails were meticulously tailored and multilingual, crafted in Korean, English, Persian, Arabic, French, and Russian. Most emails were timed to coincide with real diplomatic events, enhancing their credibility.

Technical Delivery and Malware Capabilities

To evade typical email defenses, attackers delivered password‑protected ZIP archive attachments hosted on cloud services such as Dropbox, Google Drive, and South Korea’s Daum. Inside these archives lay a .LNK file masquerading as a PDF. When executed, the shortcut ran obfuscated PowerShell code that fetched the XenoRAT payload from GitHub or Dropbox, then established persistence via scheduled tasks.

XenoRAT is a powerful trojan capable of logging keystrokes, capturing screenshots, and accessing webcam and microphone. It supports file transfers, remote shell functionality, and stealthy, in‑memory loading via reflection, protected by Confuser Core 1.6.0 obfuscation.

Attribution: Kimsuky… or Something Else?

Trellix notes that the campaign reflects hallmarks of APT43/Kimsuky — including use of Korean‑language services, GitHub‑based command and control, and consistent GUID and mutex usage across malware families.

However, analysis of the attackers’ working hours reveals alignment with Chinese time zones, including pauses during Chinese public holidays, and no significant correlation with Korean holidays. Based on this, Trellix attributes the operation to Kimsuky with medium confidence, suggesting potential Chinese sponsorship, support, or even operational coordination.

Implications

This campaign highlights a refined trend in cyber-espionage: the use of legitimate cloud services and developer platforms like GitHub for stealthy command-and-control and malware distribution. The targeted, context-aware phishing execution underscores the importance of heightened vigilance among diplomatic and governmental organizations.

Mitigation Recommendations

  1. User Training: Educate staff — particularly diplomatic and administrative personnel — on identifying spear-phishing, especially multilingual, tailored, and event-timed messages.
  2. Email Defenses: Enhance filtration to flag encrypted ZIP attachments and unusual .LNK files. Alert on incoming items from cloud storage links loaded with passwords in the message.
  3. Access Control: Implement robust auditing of GitHub and Dropbox usage. Limit access scopes, rotate tokens frequently, and monitor for anomalous pull or access behavior.
  4. Endpoint Monitoring: Deploy tools to detect reflection-based in-memory execution and obfuscated PowerShell. Monitor for scheduled tasks being created outside standard administrative procedures.
  5. Incident Response Readiness: Establish swift token revocation protocols for suspected compromised credentials. Coordinate with cloud providers (GitHub, Dropbox) to trace suspicious traffic and activity.

In summary, the XenoRAT campaign is a chilling reminder of how advanced persistent threats are refining both their social engineering and technical evasion strategies. Diplomats and governments must counter not only phishing, but the abuse of trusted platforms and services.

Please subscribe to the Newsletter so that you do not miss any critical update

Leave a Reply

Your email address will not be published. Required fields are marked *