YOU ARE VIEWING ONE ITEM FROM THE AICRIER FEED

Kimsuky weaponizes OpenCode agent for phishing decoys

AICrier tracks AI developer news across Product Hunt, GitHub, Hacker News, YouTube, X, arXiv, and more. This page keeps the article you opened front and center while giving you a path into the live feed.

// WHAT AICRIER DOES

7+

TRACKED FEEDS

24/7

SCRAPED FEED

Short summaries, external links, screenshots, relevance scoring, tags, and featured picks for AI builders.

Kimsuky weaponizes OpenCode agent for phishing decoys
OPEN LINK ↗
// 1h agoSECURITY INCIDENT

Kimsuky weaponizes OpenCode agent for phishing decoys

Cybersecurity firm Genians revealed that threat group Kimsuky has evolved its Operation GitPower campaign by integrating the open-source AI coding agent OpenCode to mass-produce spear-phishing decoys. Forensic analysis of malicious shortcut files and decoy PDFs identified OpenCode in document metadata alongside synchronized timestamps and unedited placeholders, confirming autonomous agents are being deployed directly in attack staging pipelines.

// ANALYSIS

Threat actors have progressed from asking chatbots to draft phishing emails to plugging autonomous AI coding agents directly into automated malware and lure-generation pipelines, sacrificing operational hygiene for scale. The explicit presence of OpenCode and HeadlessChrome in PDF metadata demonstrates automated workflows generating lures and rendering HTML templates to PDFs in bulk. Synchronized batch timestamps and unedited artifacts like placeholders prove these campaigns outpace human review. Defending against agent-driven attacks now requires inspecting file structural anomalies, browser-automation metadata signatures, and unusual GitHub token traffic rather than relying on document appearance.

// TAGS
kimsukyopencodecybersecuritythreat-intelligencegenerative-aispear-phishingmalwareoperation-gitpower

DISCOVERED

1h ago

2026-09-11

PUBLISHED

19h ago

2026-09-10

RELEVANCE

8/ 10

AUTHOR

rst_cloud