Kimsuky Poses as Diplomats in LNK Phishing

AhnLab ASEC · High sophistication
Last updated July 30, 2026

AhnLab reports real-world spear-phishing attacks by the Kimsuky group that impersonate diplomatic personnel and trick targets into opening disguised LNK “document” attachments. Opening the fake document launches scripts that install tools like the PebbleDash backdoor and PrxClient proxy, enabling remote control and data theft. The campaign is described as targeting people in the education sector and using diplomatic-themed decoy files to look legitimate.

How the Attack Worked

This campaign, attributed by AhnLab to the Kimsuky group, relies on spear-phishing emails that impersonate diplomatic personnel. Victims receive what appears to be a document attachment, such as one named to resemble a PDF, but the file is actually an LNK shortcut. Filenames observed include "D.21 SEOUL.Lnk," "AIE NO. 178 SEOUL.Lnk," and a heavily padded name using dots and spaces to hide the true .Lnk extension. When the victim opens the file expecting a document, it instead triggers a script chain, launching tools like Mshta and PowerShell, which act as a dropper for further payloads.

The Payloads Behind the Lure

Once the script chain executes, it installs the PebbleDash backdoor and the PrxClient proxy malware, along with additional tools used for privilege escalation and keylogging. This combination gives an attacker remote control over the compromised system and a path to steal information stored locally, including credentials and other sensitive data.

Why It Succeeded

The lure works because the attachment is disguised to look like an ordinary document, and the decoy content itself carries diplomatic-related themes to reinforce the impersonation. Recipients expecting routine correspondence from a diplomatic contact have little reason to suspect that opening the file will run a script rather than open a document viewer. The use of an LNK file instead of a more commonly flagged executable format also helps the attachment blend in with everyday file traffic.

What to Watch For

  • Attachments with a .Lnk extension rather than .pdf or .docx, even if the filename looks document-like
  • Filenames padded with excessive dots or spaces, which can be used to hide the real file extension
  • Unexpected outreach that claims to come from diplomatic personnel, particularly directed at education-sector staff
  • Any attachment that triggers a script or installer process instead of opening in a normal viewer

Building Resistance

AhnLab notes that this campaign has recently focused on individuals working in the education sector, including faculty, researchers, and administrative staff, making targeted awareness training for this group a priority. Organizations should reinforce that file extensions matter more than filenames, verify unexpected requests from high-trust external contacts such as diplomatic staff before opening attachments, and treat any script-driven behavior following an attachment open as a signal to isolate the system and investigate. Combining user awareness with technical controls that flag LNK attachments in email can reduce the chance that this type of disguised-document lure leads to a successful compromise.

Key findings

  • Attackers impersonated diplomatic personnel and used diplomatic-themed decoy documents to entice victims.
  • The lure relied on LNK files disguised as documents (e.g., PDF-looking filenames) that executed scripts to install malware.
  • Payloads included PebbleDash (backdoor) and PrxClient (proxy), plus tooling for privilege escalation and keylogging.
  • AhnLab states the campaign recently targeted individuals working in the education sector.

Who’s being targeted

  • Commonly targeted roles: Education staff, Faculty, Researchers, Administrative staff, IT / Helpdesk (for attachment handling guidance).
  • Affected industries: Education, Government / Public sector (diplomatic theme / impersonation).
  • Attack channels: email.
  • Impersonated: Diplomatic personnel.

Red flags to watch for

  • Attachment is a .Lnk file rather than a .pdf/.docx
  • Filename is made to look like a document but is executable
  • Unexpected diplomatic outreach to education-sector staff
  • “PDF” is actually a .Lnk file
  • Excessive dots/spaces in filename to hide the real extension
  • Attachment launches scripts (PowerShell/mshta) instead of opening a document
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the Kimsuky LNK phishing attack?

It is a spear-phishing campaign in which attackers impersonate diplomatic personnel and send LNK files disguised as documents, such as PDFs, that install backdoor and proxy malware when opened.

Who is being targeted by this campaign?

AhnLab reports the campaign has recently targeted individuals working in the education sector, including faculty, researchers, and administrative staff.

What malware does the attack install?

The LNK files execute scripts that install the PebbleDash backdoor and PrxClient proxy malware, along with tools for privilege escalation and keylogging.

How can I spot one of these malicious attachments?

Watch for attachments with a .Lnk extension disguised to look like a .pdf or .docx, especially with excessive dots or spaces used to hide the real file extension.

Read the video transcript

You get an email from a “diplomat” to your campus inbox: “Please review the attached document.” Looks important, right? But this “document” is actually an LNK shortcut. Names like “vvn.31.Pdf………….Lnk” hide the real extension. When you open it, it doesn’t show a real PDF; it quietly runs PowerShell and mshta to drop PebbleDash and PrxClient for remote control and data theft. Here’s the gotcha: Kimsuky is sending these to people in the education sector, impersonating diplomatic personnel and using diplomatic-themed decoy files. The only thing that gives it away? The attachment isn’t a real .pdf or .docx at all, it’s .Lnk. So if a “diplomat” sends you a document and the attachment ends in .Lnk, stop. Don’t open it, report the email to security and delete it.

Similar attacks

Larva-24009 Lures Firms With Fake Doc Attachments

Larva-24009 Lures Firms With Fake Doc Attachments

AhnLab reports Larva-24009 has continued phishing campaigns through 2026, sending emails that trick employees into opening fake “document” attachments that are actually shortcut (LNK) files. When opened, the attachment runs hidden PowerShell commands, shows a decoy document, and silently downloads…

August 3, 2026
Korea Flags Job-Offer Phish + Watering Holes

Korea Flags Job-Offer Phish + Watering Holes

South Korean agencies warned that a state-backed hacking group is actively targeting citizens and businesses using job-themed phishing emails and “watering hole” attacks on legitimate websites. The phishing lures include fake job applicants sending resume links and impersonated recruiters sending…

July 31, 2026
Invoice Phish Drops ValleyRAT via BYOVD Drivers

Invoice Phish Drops ValleyRAT via BYOVD Drivers

Researchers reported a real campaign by the China-based Silver Fox group against a Japanese industrial manufacturer. The attack starts with an invoice-themed phishing message that leads victims to open a ZIP file, triggering a DLL sideloading chain and installing ValleyRAT for persistent remote…

July 30, 2026
Fake Claude App and Alert Apps Drive New Scams

Fake Claude App and Alert Apps Drive New Scams

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude desktop app, a fake emergency alert app, and banking-malware phishing). The common pattern is “looks normal, feels urgent,” leading users to…

July 23, 2026
Kimsuky Uses AI-Polished Phishing Lures

Kimsuky Uses AI-Polished Phishing Lures

Researchers say North Korea-linked Kimsuky is using AI tools to improve phishing campaigns that deliver malware through ZIP files containing malicious Windows shortcut (LNK) files. The lures are designed to look like legitimate international event materials, research reports, or meeting requests,…

August 10, 2026
Korean Spear-Phishing Drops Xctdoor via LNK

Korean Spear-Phishing Drops Xctdoor via LNK

Researchers report real-world attacks in Korea where victims are tricked into opening shortcut (LNK) files or “security software” installers that secretly install the Xctdoor backdoor. The lures use believable filenames (e.g., account statements, lease documents, resumes) and fake installers (e.g.,…

August 6, 2026