Kimsuky Deploys Malicious LNK Files to Implant Python-Based Backdoor in Multi-Stage Attack

2026-04-14 Excalibra

https://medium.com/meetcyber/kimsuky-deploys-malicious-lnk-files-to-implant-python-based-backdoor-in-multi-stage-attack-2caa185b5361

Thumbnail for Kimsuky Deploys Malicious LNK Files to Implant Python-Based Backdoor in Multi-Stage Attack

Kimsuky is reported to have evolved its malicious LNK delivery by disguising shortcut files as HWP documents and adding XML, VBS, PowerShell, BAT, ZIP, and Python stages before final malware execution. Recent samples create a hidden C:\windirr directory, drop decoy documents, register XML-based scheduled tasks such as GoogleUpdateTaskMachineCGI__{56C6A980–91A1–4DB2–9812–5158E7E97388}, and run staged scripts on a recurring schedule. The chain abuses Dropbox both to exfiltrate host information under filenames containing the user domain and date and to retrieve additional components that unpack into C:\winii. The final Python backdoor beacons to 45.95.186[.]232:8080 with the string HAPPY and supports shell execution, drive enumeration, file upload and download, file deletion with overwrite, and execution of EXE, BAT, and VBS files.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://qugesr.online/m/bDw 2026-04-01 2026-04-14
DOMAIN qugesr.online 2026-04-01 2026-04-14
IPv4 45.95.186.232 2026-04-01 2026-04-14

Related Actors

Related Reports

« Back