DPRK-linked actors use GitHub C2 and LNK phishing in South Korea, enabling persistent PowerShell control and data ...
A single unauthenticated connection gives attackers a full shell; credential theft observed in under three minutes on honeypot servers.