Kimsuky Uses LNK, JSE Lures to Target Recruiters, Crypto Users, Defense Officials
ID: b069e79f-e966-5ea2-bf67-c4e5b26b0b7f
STIX ID: report--b069e79f-e966-5ea2-bf67-c4e5b26b0b7f
Feed Name: GBHackers
Kimsuky conducted at least four tailored spear-phishing campaigns in early 2026 targeting recruiters, crypto users/developers, defense personnel, and academic/public sector staff; attackers used deceptive LNK and JSE lures (hidden extensions), delivered payloads via embedded decoy documents and ZIPs, established persistence through scheduled tasks and Startup entries, and abused trusted services (GitHub, Microsoft CDN, VSCode tunnels) for C2 and payload hosting—enabling stealthy long-term access and data exfiltration while evading reputation-based detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
