logo

A malicious LNK that spreads a Python-based backdoor and how it’s spreading (Kimsuky group)

ID: 5a8203e2-d854-59e3-8a55-9c2e810ffb30

STIX ID: report--5a8203e2-d854-59e3-8a55-9c2e810ffb30

Feed Name: ASEC

Threat Score
78/100

Date Published: 2026-04-01

Date Updated: 2026-05-13

Author: ATCP

...
...

This report analyzes a Kimsuky campaign that altered its LNK-based delivery to a multi-stage chain (LNK → PowerShell → generated XML/VBS/PS1/BAT), ultimately executing Python downloaders/backdoors; it documents task scheduler XML usage, Dropbox as a C2/exfiltration channel, file hashes, URLs/domains, a C2 IP (45.95.186.232:8080), and observed attacker commands used to enumerate drives, run shell commands, and transfer files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.