logo

Kimsuky Uses LNK, JSE Lures to Target Recruiters, Crypto Users, Defense Officials

ID: b069e79f-e966-5ea2-bf67-c4e5b26b0b7f

STIX ID: report--b069e79f-e966-5ea2-bf67-c4e5b26b0b7f

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Mayura Kathir

...
...

Kimsuky conducted at least four tailored spear-phishing campaigns in early 2026 targeting recruiters, crypto users/developers, defense personnel, and academic/public sector staff; attackers used deceptive LNK and JSE lures (hidden extensions), delivered payloads via embedded decoy documents and ZIPs, established persistence through scheduled tasks and Startup entries, and abused trusted services (GitHub, Microsoft CDN, VSCode tunnels) for C2 and payload hosting—enabling stealthy long-term access and data exfiltration while evading reputation-based detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.