#LINKON
Malware/Tool
2024-08-22 • Threat Tracking: Analysis of puNK-003’s Lilith RAT ported to AutoIt Script
LINKON is a Windows LNK dropper used by KONNI-linked operators. The shortcut embeds files and an obfuscated PowerShell command; execution drops and opens a decoy document while writing additional components to disk. Related KONNVBS and KONNBAT scripts can establish persistence through Windows Task Scheduler and download further files from hard-coded attacker infrastructure. Reporting distinguishes LINKON’s dropper role from CURKON, a visually similar LNK used by another tracked cluster as a downloader for AutoIt-based payloads.
-
2
Tagged Reports
-
1
Unique Authors
-
177
Active Days