Kimsuky weaponizes OpenCode agent for phishing decoys
Cybersecurity firm Genians revealed that threat group Kimsuky has evolved its Operation GitPower campaign by integrating the open-source AI coding agent OpenCode to mass-produce spear-phishing decoys. Forensic analysis of malicious shortcut files and decoy PDFs identified OpenCode in document metadata alongside synchronized timestamps and unedited placeholders, confirming autonomous agents are being deployed directly in attack staging pipelines.
Threat actors have progressed from asking chatbots to draft phishing emails to plugging autonomous AI coding agents directly into automated malware and lure-generation pipelines, sacrificing operational hygiene for scale. The explicit presence of OpenCode and HeadlessChrome in PDF metadata demonstrates automated workflows generating lures and rendering HTML templates to PDFs in bulk. Synchronized batch timestamps and unedited artifacts like placeholders prove these campaigns outpace human review. Defending against agent-driven attacks now requires inspecting file structural anomalies, browser-automation metadata signatures, and unusual GitHub token traffic rather than relying on document appearance.
DISCOVERED
1h ago
2026-09-11
PUBLISHED
19h ago
2026-09-10
RELEVANCE
AUTHOR
rst_cloud
