logo

Kimsuky Uses Malicious LNK Files to Drop Python Backdoor

ID: b646c02c-8f25-5174-b05a-0d0202e65bed

STIX ID: report--b646c02c-8f25-5174-b05a-0d0202e65bed

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-04-03

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Kimsuky is running a sophisticated, multi-stage campaign using malicious LNK files that kick off PowerShell and a fragmented XML→VBS→PS1→BAT chain to install a Python backdoor; the attackers use Task Scheduler XML imports, Dropbox for C2/exfiltration, bundled Python runtimes for persistence, and artifacts placed in stealth folders (e.g., C:\windirr, C:\winii). The backdoor implements a custom protocol, remote command execution, file upload/download and secure deletion, and the report provides IOCs (task names, filenames, C2 IP) and defender guidance to monitor scheduler imports, suspicious folders, Dropbox traffic, and bundled Python interpreters.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.