Published: September 9, 2025
1
22
68

#ElasticSecurityLabs saw phishing campaigns deploying LNK files masquerading as PDFs ([.]pdf[.]lnk) to load a Rust-based implant, using Discord C2 via the serenity crate. Bot Token/Server ID were AES-encrypted and Base64-encoded; for our PoC, we used our own.

Image in tweet by Elastic Security Labs

Example infection chain: HuangWenNi-Resume[.]pdf[.]lnk -> executes PowerShell to display HuangWenNi-Resume[.]pdf -> downloads archive from hxxps://wsbcard[.]s3[.]dualstack[.]us-east-1[.]amazonaws[.]com/test/code[.]zip -> extracts & runs code.exe.

Image in tweet by Elastic Security Labs

IOC’s: wsbcard[.]s3[.]dualstack[.]us-east-1[.]amazonaws[.]com HuangWenNi-Resume[.]pdf[.]lnk - d1d573f2c028928ff7b0db6a314674ca THÔNG_BÁO_KIỂM_TRA_TÀI_CHÍNH_KHẨN_CẤP[.]pdf[.]lnk - c8d3b6ef43c63ae24114b037e320c6d6

Image in tweet by Elastic Security Labs

IOC’s, cont’d: VPN_LDAP_huong_dan_su_dung_ver2.1[.]pdf[.]lnk - 3cef82b2a9160ab0116f0cc134468f0a code[.]zip - 68682bcbd032f8198a98a024f8da3159 notepad[.]zip - 6c91cc0de981ce8ba2b7c975e18fd43c

Image in tweet by Elastic Security Labs

So this was a fun one to investigate! We had a threat actor install our agent, and it gave us some insight into what they do for a "living." 👇 https://www.huntress.com/blog/...

Excited to share our latest research on APT37(a.k.a ScarCruft, Ruby Sleet, and Velvet Chollima)’s new infection chain and C2 operation: 1⃣ Initial Access: Leveraging LNK and CHM files to deliver Rust-based and PowerShell-based malware. 2⃣ Post-Recon: Deployment of FadeStealer

Image in tweet by Elastic Security Labs
Image in tweet by Elastic Security Labs

Guys, the week hasn't even started SessionReaper, a critical bug in Magento & Adobe Commerce (CVE-2025-54236) https://sansec.io/research/ses...

Image in tweet by Elastic Security Labs
Image in tweet by Elastic Security Labs

APT37 Targets Windows with Rust Backdoor and Python Loader C2 Server https://www.zscaler.com/blogs/...

Image in tweet by Elastic Security Labs

Share this thread

Read on Twitter

View original thread

Navigate thread

1/8