Kimsuky Group Uses Malicious LNK Files to Deploy Python-Based Backdoor

Kimsuky Group Uses Malicious LNK Files to Deploy Python-Based Backdoor

First seen 3 Apr 2026, 15:01 UTC Asec.AhnlabGbhackersCybersecuritynewsSocprime 83% similarity 60.0

Article Content

Browse articles
ThreatCluster

The Kimsuky group, a North Korean threat actor, has been identified using malicious LNK files to deliver a Python-based backdoor to victim systems. This attack method involves multiple stages, making it difficult for security tools to detect the final payload. AhnLab's recent findings indicate a structural change in the intermediate execution phase of the attack, although the overall flow remains consistent with previous campaigns. The specific impact scope and number of affected systems have not been disclosed. The campaign is ongoing, with security experts urging vigilance against this evolving threat. The use of LNK files as a delivery mechanism highlights a persistent trend in targeted cyberattacks. Organizations should be aware of this method to enhance their defensive measures.

Key Points: • Kimsuky group employs malicious LNK files to install a Python-based backdoor. • The attack features multiple stages, complicating detection efforts. • Recent changes in the attack's execution phase have been observed.

ThreatCluster AI How this analysis works

Timeline

2026-04-01
AhnLab reports on Kimsuky group’s new attack method.
2026-04-03
Cybersecuritynews publishes details on Kimsuky’s campaign.

Community

Browse all →

Tracked Entities in This Story