FortiGuard Labs has uncovered a DPRK-linked attack campaign targeting South Korean organizations using malicious LNK files as the initial infection vector. The attacks employ a multi-stage execution chain: LNK files drop decoy PDFs while silently executing PowerShell scripts that check for analysis environments (VMs, debuggers, forensic tools), establish persistence via scheduled tasks running VBScript every 30 minutes, and exfiltrate system and network data. Notably, the threat actor abuses GitHub's API as covert C2 infrastructure, storing payloads and receiving exfiltrated logs in private repositories under accounts like 'motoralis'. This approach exploits GitHub's trusted reputation to bypass corporate security filters. The campaign uses LolBins (Living off the Land Binaries) to minimize dropped PE files and evade detection, with decoy PDFs themed around Korean business proposals to lend credibility to the phishing lures.