A threat actor assessed as Kimsuky distributed malicious Windows shortcut (.LNK) files to South Korean targets, posing as a request to review a seafood-ingredient purchase document. Opening the shortcut displays a legitimate-looking HWP decoy while covertly launching PowerShell and obfuscated JavaScript payloads. The malware creates persistence through scheduled tasks, reportedly using names matching MicrosoftOffice2016_<UUID-prefix>, and removes or hides intermediate files and temporary CMD artifacts to hinder investigation.
The PowerShell payload inventories host and user information, including system and process details, then exfiltrates it to a Backblaze B2 cloud-storage-based command-and-control infrastructure. It also retrieves victim-specific follow-on commands from that service and executes them in a hidden window. AhnLab linked the activity to prior Kimsuky operations based on overlapping PowerShell syntax, LNK data-extraction behavior, file-size-based LNK identification, and scheduled-task registration patterns; defenders should hunt for the named task pattern, suspicious ProgramData artifacts, Backblaze B2 traffic, and connections to api.ipify.org.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
AhnLab identified distribution of a malicious LNK file masquerading as a seafood-ingredient purchase-review request to users in South Korea. The LNK displayed an HWP decoy while deploying PowerShell and JavaScript payloads, establishing scheduled-task persistence, exfiltrating host information through Backblaze B2, and retrieving follow-on commands; AhnLab linked the activity to Kimsuky based on similarities with prior campaigns.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
infosec.pub
Open sourcemalware.news
Open sourcebsky.app
Open sourceasec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.