← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Malicious LNKs distributing Python-based backdoors and changes in distribution methods (Kimsuky Group)
The Kimsuky Group has recently modified its tactics for distributing malicious LNK files, which are designed to execute a Python-based backdoor or downloader. While the overall attack flow remains consistent, a notable structural change in the intermediate execution phase has occurred. The new workflow involves a sequence where a PowerShell script executed from the LNK file downloads a BAT file, which subsequently triggers the download of a ZIP file containing a Python script, an interpreter, and an XML task scheduler.
MITRE ATT&CK & Malware Families
Indicators of Compromise (5 / 17 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 059bb6c439ffedc61d9168c23552202c | — | 2026-04-04 | |
| FileHash-MD5 | 0633d5f93a5f08a909c039a3f7e90830 | — | 2026-04-04 | |
| FileHash-MD5 | 063faa06c63e4091ff8df4acffeb10be | — | 2026-04-04 | |
| FileHash-MD5 | 130ce31e1fe7c0aa5fae32d96afff4c6 | — | 2026-04-04 | |
| FileHash-MD5 | 2052261efb1e9d486997fc1795d7d489 | — | 2026-04-04 |
References (1)