Kimsuky Deploys Malicious LNK Files to Deliver Python-Based Backdoor in Multi-Stage Attack
ID: c29557fc-e82e-52a4-935f-ec4827d51517
STIX ID: report--c29557fc-e82e-52a4-935f-ec4827d51517
Feed Name: cybersecurityNews.com
Kimsuky has conducted a stealthy multi-stage campaign that begins with malicious .lnk files masquerading as documents and progresses through concealed PowerShell, XML, VBS, PS1 and BAT stages to deploy a Python backdoor (beauty.py). The report documents persistence via scheduled tasks (Google-themed task names), use of Dropbox for data exfiltration and hosting, the final C2 45.95.186.232:8080, and post-compromise capabilities including command execution, file transfer, and reconnaissance, and recommends avoiding opening LNKs, monitoring Task Scheduler, and hardening endpoint controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
