Kimsuky Hackers Use LNK and JSE Lures to Target Recruiters, Crypto Users, and Defense Officials
ID: 5351036e-d3f9-5b9a-99c7-51104c15dea6
STIX ID: report--5351036e-d3f9-5b9a-99c7-51104c15dea6
Feed Name: cybersecurityNews.com
Kimsuky conducted four sophisticated spear-phishing campaigns in the first half of 2025 targeting recruiters, crypto users, defense sector officials, and graduate school staff using LNK and double-extension JSE decoys that displayed benign documents while deploying payloads that disabled UAC, registered Defender exceptions, established Task Scheduler persistence, and established C2 channels via GitHub, Microsoft CDN and VSCode tunnels; LogPresso’s analysis includes detailed IoCs and recommends behavior-based detection to counter this adaptive, nation-state-linked threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
