LNK files
-
DPRK-linked hackers use GitHub as command hub in South Korea attacks
DPRK-linked hackers used GitHub as command and control infrastructure in attacks on South Korean organizations, Fortinet said. The campaigns relied on LNK files, PowerShell, persistence tasks and trusted cloud services to hide activity.
-
Russian-origin CTRL toolkit spread through malicious Windows shortcut files, researchers say
Researchers say a Russian-origin toolkit called CTRL was spread through malicious Windows shortcut files disguised as private key folders. The malware adds phishing, keylogging, RDP hijacking and reverse tunneling while limiting network traces.


