2026-07-30 13:59 UTC
🚨 A malicious LNK disguised as a PDF leads to DARTHVADER stealer deployment & persistence, turning a document-like lure into post-click compromise.
Observed behavior: LOLBin and AutoIt execution, hidden cmd.exe activity, curl.exe downloads, PowerShell ExecutionPolicy Bypass, mutex creation, cmd.exe /V:ON for delayed environment variable expansion, and /D to disable AutoRun command processing.
💻 Live detonation and IOCs for detection & response: https://app.any.run/tasks/81e896a9-849b-491f-8dc4-edd51fed632b/?utm_source=mastodon&utm_medium=post&utm_campaign=darthvader_lnk&utm_term=300726&utm_content=linktoservice
⚡️ Learn how #ANYRUN helps SOC teams detect complex threats early: https://any.run/enterprise/?utm_source=mastodon&utm_medium=post&utm_campaign=darthvader_lnk&utm_term=300726&utm_content=linktoenterprise
#cybersecurity #infosec
Replies (0)
No replies.