PULSE NAME
Threat Actors Using LNK Files and GitHub for Stealthy C2 Operations
WHITE cryptocti 2026-04-03 Modified: 2026-04-03
11
IOCs
MEDIUM VOLUME
Attackers launch phishing campaigns using malicious LNK files disguised as PDFs to deliver hidden PowerShell scripts.
Indicators of Compromise (3 / 11 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 27e6e0a34ec234f7a1ca45997c8a1dbe MD5 of af0309aa38d067373c54b2a7774a32f68ab72cb2dbf5aed74ac784b079830184 2026-04-03
FileHash-MD5 81132c36a3738c7213e6aeada8e8c296 MD5 of 9c3f2bd300ad2ef8584cc48adc47aab61bf85fc653d923e106c73fc6ec3ea1dc 2026-04-03
FileHash-MD5 b59d53f571e76a370e256bbc265716ff MD5 of 484a16d779d67c7339125ceac10b9abf1aa47f561f40058789bfe2acda548282 2026-04-03