Thursday, September 10, 2026

DarkSamural APT Group Deploys LNK/PDF Malware to Steal Critical Information

DarkSamural, a newly identified subspecies of the notorious OceanLotus APT, has launched a sophisticated campaign targeting high-value organizations in Pakistan.

Leveraging malicious LNK files masquerading as PDF documents and sophisticated MSC containers empowered by GrimResource technology, the group delivered a multi-stage payload designed to exfiltrate critical data.

After in-depth sample and correlation analysis, cybersecurity researchers have addressed DarkSamural’s operations as a false-flag undertaking orchestrated by Patchwork.

Patchwork, also known as APT Group 72, surfaced around 2009 but only gained international prominence in 2015 when Cymmetria revealed its extensive espionage operations.

Its primary targets include military, diplomatic, educational, and scientific research institutions across China, Pakistan, and Bangladesh.

Patchwork’s hallmark is spear-phishing: crafting emails with attachments that appear innocuous but conceal malicious executables. In this campaign, the attackers exploited Windows MSC files, disguising them with PDF icons to mislead victims.

Upon opening, these containers invoke mmc.exe to load an ActiveX object, enabling embedded JavaScript to fetch and execute subsequent payloads from remote command-and-control servers.

Patchwork maintains an arsenal of proprietary and open-source tools. Their lineup includes the BADNEWS RAT for stealthy remote access, QuasarRAT and AsyncRAT for straightforward C2 communication, Mythic as a modular penetration-testing framework, commercial Remcos RAT, and NorthStarC2.

By cycling through these tools, the group ensures persistent control over compromised environments and evades signature-based defenses.

Tactics, Techniques, and Procedures

Initial compromise hinges on deceptive emails containing a compressed archive labeled as “Drone_Information.pdf.msc.” When executed, the .msc file leverages GrimResource to decrypt and run obfuscated JScript, which then downloads a second-stage HTML file named Unit-942-Drone-Info-MAK3.html.

This file contains two layers of obfuscated JavaScript. The first layer triggers an XSLT transformation via CLSID{2933BF90-7B36-11D2-B20E-00C04F983E60}, fetching additional script from a remote URL. The second layer downloads the real payload—Drone_Information.pdf—to C:\Users\Public.

To evade detection, the JavaScript is heavily obfuscated across multiple layers, while legitimate Windows utilities such as dism.exe are repurposed to sideload a malicious DLL renamed DismCore.dll.

Persistence is achieved by registering scheduled tasks named MicrosoftEdgeUpdateTaskMachineCoreXUI and creating startup entries.

Once resident, the implant writes log data to C:\ProgramData\6092E833-F189-4160-951D.log before renaming it to DismCore.dll and invoking its exported DllRegisterServer, which dynamically resolves API addresses and spawns the Mythic agent.

Correlation Findings

The Mythic agent, compiled on May 29, 2025, communicates with its C2 at https://d11d6t6zp1jvtm.cloudfront.net/data using AES-HMAC encryption.

It crafts POST requests via WinHTTP APIs, appending IV values to payloads encrypted with a shared 256-bit key. During each check-in, the implant reports host details—IP, OS, user, hostname, PID, and UUID—mirroring legitimate Mythic traffic patterns.

The checkin flag in the action field of this sample, the online packet data structure, and the encryption method ( AES-128-GCM ).

Notably, the HTML lure page contains Vietnamese-language branding claiming affiliation to Dark Samurai, suggesting a deliberate misdirection.

Correlation analysis of these domains and additional Protego samples led researchers to attribute the entire operation to Patchwork, marking DarkSamural as a purposeful false-flag designed to sow confusion among threat intelligence communities.

As the campaign unfolds, organizations in South Asia and beyond must reinforce email filtering, scrutinize seemingly benign document files, and employ behavioral detection capable of parsing multi-layered scripts.

With Patchwork’s evolving toolkit, defenders face a formidable adversary adept at deception and rapid toolchain rotation.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News