logo

Kimsuky Deploys Malicious LNK Files to Deliver Python-Based Backdoor in Multi-Stage Attack

ID: c29557fc-e82e-52a4-935f-ec4827d51517

STIX ID: report--c29557fc-e82e-52a4-935f-ec4827d51517

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-04-03

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

Kimsuky has conducted a stealthy multi-stage campaign that begins with malicious .lnk files masquerading as documents and progresses through concealed PowerShell, XML, VBS, PS1 and BAT stages to deploy a Python backdoor (beauty.py). The report documents persistence via scheduled tasks (Google-themed task names), use of Dropbox for data exfiltration and hosting, the final C2 45.95.186.232:8080, and post-compromise capabilities including command execution, file transfer, and reconnaissance, and recommends avoiding opening LNKs, monitoring Task Scheduler, and hardening endpoint controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.