Exploiting Microsoft CMSTP With Malicious LNK Files
ID: 19f088d7-a6fb-5ee8-bad5-9f0e61515413
STIX ID: report--19f088d7-a6fb-5ee8-bad5-9f0e61515413
Feed Name: Cyble Blog
This report analyzes a multi-stage campaign that begins with malicious .zip/.iso attachments containing LNK files which fetch obfuscated HTA/VBScript and PowerShell loaders; the chain uses AES-encrypted payloads and abuses cmstp.exe with a crafted INF to bypass UAC and execute payloads (RedLine, Blank Grabber, NetSupport RAT). The analysis includes decoding techniques, process and network behavior, numerous IOCs (URLs and hashes), a YARA rule, and recommendations to block suspicious CMSTP command lines and harden email filtering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
