Malicious LNK Files Distributing a Python-Based Backdoor and Changes in Distribution Techniques (Kimsuky Group)

2026-04-01 Ahnlab

https://asec.ahnlab.com/en/93151/

Thumbnail for Malicious LNK Files Distributing a Python-Based Backdoor and Changes in Distribution Techniques (Kimsuky Group)

AhnLab ASEC observed Kimsuky changing its malicious LNK distribution chain while still ultimately executing Python-based backdoors or downloaders. Recent LNK lures such as resume and data backup guide files create hidden components under C:\windirr, then use XML Task Scheduler entries, VBS, PowerShell, BAT files, Dropbox, and staged ZIP downloads before running beauty.py. The Python backdoor connects to 45.95.186[.]232:8080, sends a “HAPPY” infection signal, and uses a custom magic-byte protocol for shell execution, drive and directory listing, file transfer, deletion, and launching BAT/VBS/EXE files. AhnLab links the activity to Kimsuky through similar scheduler names, sch_*.db XML task files, reused decoys, and the group’s pattern of disguising LNK files as documents to evade user suspicion and detection.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://qugesr.online/m/bDw 2026-04-01 2026-04-14
DOMAIN qugesr.online 2026-04-01 2026-04-14
IPv4 45.95.186.232 2026-04-01 2026-04-14
URL https://quickcon.store/man/logo… 2026-04-01 2026-04-01
URL https://qugesr.online/dwparts_v… 2026-04-01 2026-04-01
URL https://qugesr.online/dwparts_v… 2026-04-01 2026-04-01
URL https://quickcon.store/man/logo… 2026-04-01 2026-04-01
URL Https://quickcon.store/man/logo… 2026-04-01 2026-04-01
URL https://qugesr.online/dwparts_v… 2026-04-01 2026-04-01
DOMAIN quickcon.store 2026-04-01 2026-04-01

Related Actors

Related Reports

« Back