« Reports in 2026

593 reports

2026-06-22 • 0x00sec

Kimsuky's DEEP#DRIVE initial-access chain used phishing-delivered LNK files disguised as documents to launch hidden PowerShell, retrieve hosted scripts and payloads, and open a decoy PDF. The emulation reproduces scheduled-task persistence and payload exe…

#Kimsuky #Phishing #LNK