Skip to content
Malicious LNK Files Disguised as Documents Deliver Fileless Malware

Malicious LNK Files Disguised as Documents Deliver Fileless Malware

First seen 19 Jun 2026, 16:22 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 20, 2026 at 15:52 UTC
  • Malicious LNK files are disguised as legitimate documents to trick users.
  • The attack employs obfuscated PowerShell commands for fileless malware delivery.
  • Organizations must enhance user training and monitor suspicious activities.

Threat actors are distributing malicious LNK files disguised as privacy consent forms and resumes to deceive users into executing them. Once opened, these files execute obfuscated PowerShell commands that download and run additional payloads using fileless techniques. The attacks aim to steal information and establish a backdoor for persistent access. Organizations are advised to enforce strict verification of file extensions and monitor PowerShell execution logs, Task Scheduler activity, and outbound connections. Users should be trained to validate incoming files before opening them. The attacks exploit common user behavior, making them particularly dangerous. Current investigations are ongoing to assess the full scope of the impact and identify affected systems. No specific numbers or CVEs were reported in the articles.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 92d ago How this analysis works

Timeline

2026-06-18
Cyberattack targeting corporate employees reported
Hackers distributed malicious LNK files disguised as resumes, leading to infections upon opening.
Cybersecuritynews
2026-06-19
Fake privacy consent LNK files identified
Malicious LNK files disguised as privacy consent forms were found to execute obfuscated PowerShell commands.
Socprime

More articles in this cluster (2)

Following this threat?

Track Xctdoor in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed