Thursday, February 27, 2025
HomeCVE/vulnerabilityTurla Hackers Weaponizing LNK-Files To Deploy Fileless Malware

Turla Hackers Weaponizing LNK-Files To Deploy Fileless Malware

Published on

SIEM as a Service

Follow Us on Google News

Hackers often weaponize LNK files because they can carry malware into systems undetected by anyone. LNK files are shortcuts that, when opened, launch a malicious payload (like scripts or executables).

LNK files are widely used in Windows environments and can easily pass themselves off as genuine files, making it hard for users to suspect their evil motives.

Cybersecurity researchers at GDataSoftware recently discovered that Turla hackers had been actively weaponizing the LNK files to deploy fileless malware.

Turla Hackers Weaponizing LNK-Files

Turla hackers have targeted Philippine companies and organizations, and to do so, they utilize a hacked media website to distribute malicious code.

Join our free webinar to learn about combating slow DDoS attacks, a major threat today.

The chain begins with a harmful shortcut, which pretends to be an official advisory from the Philippine Statistics Authority.

When applied, it sets off a PowerShell script that uses msbuild.exe from Microsoft to launch a fileless backdoor around application whitelisting.

This malware is set to run every 30 minutes via scheduled tasks. To ensure it is not detected and hard to reverse engineer, its payload is an MSIL binary protected by SmartAssembly.

TURLA infection flow (Source – GDataSoftware)

Interestingly, this incident brings together Siem Reap in Cambodia like Angkor Wat’s annual troop of tourists – social engineering, fileless malware, and legitimate system tools all being utilized in one attack.

This sophisticated backdoor has used several evasion techniques to prevent its detection. It disables ETW, patches its copies in memory, and avoids AMSI.

Malicious software establishes contact with its C2 server using an infected personal website. It first checks out a routine through a URL and then gets orders from another URL.

This multi-step communication enables the attacker to remain in control without being detected by the defenses, which shows how advanced this threat is.

Analysis of this malware shows that it has some features in common with Turla APT techniques, such as using infected websites as servers, bypassing AMSI by patching memory, executing files using PowerShell without them being on disk and executing scripts controlled by a server.

Besides this, new techniques are also used in this variant that had not previously been associated with Turla, implying possible changes in tactics within the group or that a new actor using similar methods has emerged.

Such a mix of known and unfamiliar tricks points to advanced persistent threats frequently changing their strategies. It implies that getting to know who is behind an attack remains challenging for cybersecurity researchers.

Preventions

Here below we have mentioned all the preventions:-

  • Set PowerShell to execute only signed scripts.
  • Assess and consider removing PowerShell if not needed.
  • Disable/restrict the WinRM Service to prevent remote PowerShell use.
  • Remove MSBuild.exe if not required.
  • Block msbuild.exe with application control if unnecessary.

"Is Your System Under Attack? Try Cynet XDR: Automated Detection & Response for Endpoints, Networks, & Users!"- Free Demo

Tushar Subhra
Tushar Subhra
Tushar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has...

Squidoor: Multi-Vector Malware Exploiting Outlook API, DNS & ICMP Tunneling for C2

A newly identified malware, dubbed "Squidoor," has emerged as a sophisticated threat targeting government,...

Unpatched Vulnerabilities Attract Cybercriminals as EDR Visibility Remains Limited

Cyber adversaries have evolved into highly organized and professional entities, mirroring the operational efficiency...

Threat Actors Attack Job Seekers of Fortune 500 Companies to Steal Personal Details

In Q3 2024, Cofense Intelligence uncovered a targeted spear-phishing campaign aimed at employees working...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has...

Squidoor: Multi-Vector Malware Exploiting Outlook API, DNS & ICMP Tunneling for C2

A newly identified malware, dubbed "Squidoor," has emerged as a sophisticated threat targeting government,...

Threat Actors Attack Job Seekers of Fortune 500 Companies to Steal Personal Details

In Q3 2024, Cofense Intelligence uncovered a targeted spear-phishing campaign aimed at employees working...