Stealthy Cyber Attacks: LNK Files & SSH Commands Playbook
ID: c51dff01-845b-5367-af55-c536da1575d7
STIX ID: report--c51dff01-845b-5367-af55-c536da1575d7
Feed Name: Cyble Blog
Threat Score
This CRIL report documents a trend where threat actors weaponize Windows .LNK shortcut files to run SSH commands that abuse LOLBins (scp, ProxyCommand->PowerShell/mshta, cmd->rundll32) to download and execute payloads, including stealer-like binaries; it includes three SHA-256 IoCs, a Sigma detection rule, and mitigation recommendations such as monitoring ssh.exe usage and disabling OpenSSH where unnecessary.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
