#LINKON

Malware/Tool

2024-08-22 • Threat Tracking: Analysis of puNK-003’s Lilith RAT ported to AutoIt Script

LINKON is a Windows LNK dropper used by KONNI-linked operators. The shortcut embeds files and an obfuscated PowerShell command; execution drops and opens a decoy document while writing additional components to disk. Related KONNVBS and KONNBAT scripts can establish persistence through Windows Task Scheduler and download further files from hard-coded attacker infrastructure. Reporting distinguishes LINKON’s dropper role from CURKON, a visually similar LNK used by another tracked cluster as a downloader for AutoIt-based payloads.

Tagged Reports

« Back