logo

MisterioLNK: Open-Source Builder For Malicious Loaders

ID: 3309488b-5b85-5fc9-b9d3-7a784e911668

STIX ID: report--3309488b-5b85-5fc9-b9d3-7a784e911668

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2024-10-17

Date Updated: 2026-07-20

...
...

MisterioLNK is an open-source Windows loader builder that generates obfuscated BAT, CMD, HTA, VBS, and LNK loaders to download and execute payloads; Cyble's analysis shows threat actors are using it to deploy Remcos RAT, DC RAT, and BlankStealer while many generated samples evade detection, and the report includes technical details, sample detection results, IoCs, MITRE ATT&CK mappings, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.