Cyber Security News

Hackers Trick You To Run PowerShell As Admin & Paste Their Code to Hack Windows

Microsoft Threat Intelligence has uncovered a new tactic employed by the North Korean state-sponsored hacking group Emerald Sleet, also known as Kimsuky or VELVET CHOLLIMA.

The group is leveraging social engineering techniques to trick victims into running PowerShell commands as administrators, enabling them to compromise devices and exfiltrate sensitive data.

Emerald Sleet’s latest approach involves impersonating South Korean government officials to build trust with their targets over time.

Once rapport is established, the hackers send spear-phishing emails containing PDF attachments. These emails direct victims to click on a URL under the guise of registering their devices to access the attached document.

“To read the PDF file attached to the email, the target is lured to click a URL with instructions to register their device. The registration link has instructions to open PowerShell as an administrator and paste code provided by Emerald Sleet.” Microsoft Stated in X post.

The registration process includes explicit instructions for opening PowerShell as an administrator and pasting in code provided by the attackers.

If executed, the code installs a browser-based remote desktop tool and downloads a certificate file with a hardcoded PIN from a remote server.

Device Registration and Exploitation

After installing the malicious tools, the code sends a web request to a remote server, registering the victim’s device using the downloaded certificate and PIN.

This grants Emerald Sleet unauthorized access to the compromised system, allowing them to conduct espionage and steal sensitive information.

Microsoft reports that this tactic has been observed in limited attacks since January 2025, signaling a shift in Emerald Sleet’s methods for targeting traditional espionage victims.

The group primarily focuses on individuals working in international affairs particularly those related to Northeast Asia as well as NGOs, government agencies, media outlets, and other organizations across North America, South America, Europe, and East Asia.

Microsoft is actively notifying customers who have been targeted or compromised by this activity. The company’s Defender XDR platform is capable of detecting Emerald Sleet’s tactics. To counter such threats, Microsoft recommends:

  • Investing in advanced anti-phishing solutions to detect and block malicious emails.
  • Training users on recognizing phishing attempts and avoiding suspicious URLs.
  • Applying attack surface reduction rules to block common attack techniques like malicious scripts.

This incident underscores the importance of vigilance against evolving cyber threats, particularly those targeting high-value individuals and organizations involved in sensitive international matters.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Balaji N

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…

6 minutes ago

Top 10 Best Cloud Detection & Response (CDR) Solutions in 2026

CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…

11 minutes ago

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

17 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

22 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

33 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago