Socprime Malicious LNK Files Disguised as Documents Deliver Fileless Malware
Article Content
- •Malicious LNK files are disguised as legitimate documents to trick users.
- •The attack employs obfuscated PowerShell commands for fileless malware delivery.
- •Organizations must enhance user training and monitor suspicious activities.
Threat actors are distributing malicious LNK files disguised as privacy consent forms and resumes to deceive users into executing them. Once opened, these files execute obfuscated PowerShell commands that download and run additional payloads using fileless techniques. The attacks aim to steal information and establish a backdoor for persistent access. Organizations are advised to enforce strict verification of file extensions and monitor PowerShell execution logs, Task Scheduler activity, and outbound connections. Users should be trained to validate incoming files before opening them. The attacks exploit common user behavior, making them particularly dangerous. Current investigations are ongoing to assess the full scope of the impact and identify affected systems. No specific numbers or CVEs were reported in the articles.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Xctdoor in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…