#CURKON

Malware/Tool

2024-08-22 • Threat Tracking: Analysis of puNK-003’s Lilith RAT ported to AutoIt Script

CURKON is a malicious Windows LNK downloader named by S2W and associated with the tracked puNK-003 activity cluster. When opened, it runs an embedded PowerShell command, drops and displays a decoy document, creates a hidden directory, copies curl.exe, and downloads additional files from an attacker server. Its chain retrieves AutoIt3 and an AutoIt reimplementation of Lilith RAT, which opens a reverse shell so operators can execute terminal commands on the compromised host.

Tagged Reports

« Back