logo

Exploiting Microsoft CMSTP With Malicious LNK Files

ID: 19f088d7-a6fb-5ee8-bad5-9f0e61515413

STIX ID: report--19f088d7-a6fb-5ee8-bad5-9f0e61515413

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2024-10-25

Date Updated: 2026-07-17

...
...

This report analyzes a multi-stage campaign that begins with malicious .zip/.iso attachments containing LNK files which fetch obfuscated HTA/VBScript and PowerShell loaders; the chain uses AES-encrypted payloads and abuses cmstp.exe with a crafted INF to bypass UAC and execute payloads (RedLine, Blank Grabber, NetSupport RAT). The analysis includes decoding techniques, process and network behavior, numerous IOCs (URLs and hashes), a YARA rule, and recommendations to block suspicious CMSTP command lines and harden email filtering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.