North Korea-linked threat group Kimsuky has been reported using malicious Windows shortcut (.LNK) files to initiate a multi-stage infection chain that ends with deployment of a Python-based backdoor. Reporting shared from both AhnLab and Excalibra indicates the campaign relies on weaponized LNK files as the initial access vector, with the malware delivery process evolving from earlier distribution patterns.
The activity was attributed to Kimsuky in threat-intelligence reporting and social media amplification, with references also linking the cluster to DPRK operations and possible overlap or comparison with Konni tracking. While the cited summaries did not include victimology or technical indicators, they consistently described a shift in how the group distributes malware and highlighted the use of LNK-based social engineering to stage follow-on payloads.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A Hauri report described Kimsuky using reconnaissance malware disguised as a military and security academic journal. The available reference explicitly ties the activity to Kimsuky and notes LNK and GitHub as relevant elements, but provides no further technical or victim details.
An Excalibra report outlined a multi-stage Kimsuky intrusion chain in which malicious LNK files were used as the initial infection vector to implant a Python-based backdoor. The reporting further associated the activity with DPRK-linked threat operations and Konni-related clustering context.
An AhnLab publication described Kimsuky distributing malicious LNK files to deliver a Python-based backdoor and noted changes in the group's distribution methods. The reporting linked the activity to the North Korea-aligned threat group Kimsuky.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
bsky.app
Open sourcebsky.app
Open sourcebsky.app
Open sourcebsky.app
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.