Phishing LNK files and GitHub C2 power new DPRK cyber attacks

2026-04-07T02:51:48Z6877e3fce601f11c2b93b3affeb3c9da45b84418e6b910bbf83428fd788a2e26
BKACERT-EUCISA KEVCVE-2025-53521CVE-2026-3502CVE-2026-35616DPRKDie LinkeEuropean Commission breachF5 BIG-IP APMFortiClient EMSFortinetGitHub C2LNK filesPowerShellQilin ransomwareREvilSouth KoreaTeamPCPTrueConfmalwarephishingransomwaresupply chain

What happened

Multiple high-impact incidents and active campaigns were reported: DPRK-linked actors are conducting phishing campaigns in South Korea using obfuscated .LNK files that drop a decoy PDF and PowerShell payloads and using GitHub repositories as C2 servers. German authorities (BKA) identified two alleged REvil operators tied to 130+ ransomware attacks. Thousands of F5 BIG‑IP APM appliances remain exposed and are being actively exploited via a critical RCE (CVE-2025-53521), and Fortinet issued emergency patches for an actively exploited FortiClient EMS vulnerability (CVE-2026-35616). U.S. CISA has:

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
6877e3fce601f11c2b93b3affeb3c9da45b84418e6b910bbf83428fd788a2e26
Enrichment time
2026-04-07T02:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.