Kimsuky Uses Malicious LNK Files to Drop Python Backdoor
ID: b646c02c-8f25-5174-b05a-0d0202e65bed
STIX ID: report--b646c02c-8f25-5174-b05a-0d0202e65bed
Feed Name: GBHackers
Kimsuky is running a sophisticated, multi-stage campaign using malicious LNK files that kick off PowerShell and a fragmented XML→VBS→PS1→BAT chain to install a Python backdoor; the attackers use Task Scheduler XML imports, Dropbox for C2/exfiltration, bundled Python runtimes for persistence, and artifacts placed in stealth folders (e.g., C:\windirr, C:\winii). The backdoor implements a custom protocol, remote command execution, file upload/download and secure deletion, and the report provides IOCs (task names, filenames, C2 IP) and defender guidance to monitor scheduler imports, suspicious folders, Dropbox traffic, and bundled Python interpreters.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
