Emulating Kimsuky's Initial Access
2026-06-22 • 0x00sec •
Kimsuky's DEEP#DRIVE initial-access chain used phishing-delivered LNK files disguised as documents to launch hidden PowerShell, retrieve hosted scripts and payloads, and open a decoy PDF. The emulation reproduces scheduled-task persistence and payload execution from user-writable directories while applying LNK target-spoofing techniques. Sysmon telemetry highlights `explorer.exe` spawning PowerShell and the unusual PowerShell-to-PDF-reader process lineage, for which the author provides a Defender KQL detection example. The downloaded files and Dropbox links in the post belong to the author's proof of concept rather than confirmed campaign indicators.