Threat Actors Using LNK Files and GitHub for Stealthy C2 Operations

Attackers launch phishing campaigns using malicious LNK files disguised as PDFs to deliver hidden PowerShell scripts.

Pulse ID: 69d0235ccaea90f7a7036123
Pulse Link: https://otx.alienvault.com/pulse/69d0235ccaea90f7a7036123
Pulse Author: cryptocti
Created: 2026-04-03 20:30:20

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CyberSecurity #GitHub #InfoSec #LNK #OTX #OpenThreatExchange #PDF #Phishing #PowerShell #RAT #bot #cryptocti

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange