logo

Chollima APT Hackers Weaponize LNK Files to Deploy Sophisticated Malware

ID: a06c59d9-0284-5212-b796-facd7c2f8937

STIX ID: report--a06c59d9-0284-5212-b796-facd7c2f8937

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-02-03

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

In March 2025 APT37 (Ricochet Chollima) conducted "Operation:ToyBox Story," a targeted spear-phishing campaign that used Dropbox-hosted ZIP archives with weaponized LNK shortcuts and fileless PowerShell loaders to deploy RoKRAT; the campaign uses XOR-decoded in-memory shellcode and Dropbox-based C2 to steal credentials, capture screenshots, and exfiltrate data while evading signature-based defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.