Malicious LNK Files Distributing a Python-Based Backdoor and Changes in Distribution Techniques (Kimsuky Group)
2026-04-01 • Ahnlab •
AhnLab ASEC observed Kimsuky changing its malicious LNK distribution chain while still ultimately executing Python-based backdoors or downloaders. Recent LNK lures such as resume and data backup guide files create hidden components under C:\windirr, then use XML Task Scheduler entries, VBS, PowerShell, BAT files, Dropbox, and staged ZIP downloads before running beauty.py. The Python backdoor connects to 45.95.186[.]232:8080, sends a “HAPPY” infection signal, and uses a custom magic-byte protocol for shell execution, drive and directory listing, file transfer, deletion, and launching BAT/VBS/EXE files. AhnLab links the activity to Kimsuky through similar scheduler names, sch_*.db XML task files, reused decoys, and the group’s pattern of disguising LNK files as documents to evade user suspicion and detection.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://qugesr.online/m/bDw | 2026-04-01 | 2026-04-14 |
| DOMAIN | qugesr.online | 2026-04-01 | 2026-04-14 |
| IPv4 | 45.95.186.232 | 2026-04-01 | 2026-04-14 |
| URL | https://quickcon.store/man/logo… | 2026-04-01 | 2026-04-01 |
| URL | https://qugesr.online/dwparts_v… | 2026-04-01 | 2026-04-01 |
| URL | https://qugesr.online/dwparts_v… | 2026-04-01 | 2026-04-01 |
| URL | https://quickcon.store/man/logo… | 2026-04-01 | 2026-04-01 |
| URL | Https://quickcon.store/man/logo… | 2026-04-01 | 2026-04-01 |
| URL | https://qugesr.online/dwparts_v… | 2026-04-01 | 2026-04-01 |
| DOMAIN | quickcon.store | 2026-04-01 | 2026-04-01 |