
“Case Documents” Lure Hits Law Firm via LNK
Researchers reported a real spear‑phishing intrusion against a law firm where attackers sent a message with a link to an encrypted archive. The archive…
AhnLab reports Larva-24009 has continued phishing campaigns through 2026, sending emails that trick employees into opening fake “document” attachments that are actually shortcut (LNK) files. When opened, the attachment runs hidden PowerShell commands, shows a decoy document, and silently downloads more malware used for remote access and data theft. The campaign uses business-themed topics like hospital surveys, blockchain, project documents, and resumes to look legitimate.
Larva-24009 sends phishing emails with attachments that look like ordinary documents but are actually shortcut (LNK) files. Filenames often include double extensions such as ".Docx.Lnk" along with version numbers or timestamps to appear routine. Once a recipient opens the file, it launches an obfuscated PowerShell command. To avoid raising suspicion, the malware drops a decoy document in the TEMP directory and opens it while simultaneously downloading additional PowerShell scripts in the background.
Those scripts install remote access tools including QuasarRAT and UltraVNC, and the actor may also rely on RDP for control. Persistence is maintained through scheduled tasks given legitimate-sounding names like Intel or GoogleUpdate, which helps the malware blend in with normal system activity. For data theft, the toolkit includes screenshot capture, keylogging, and NirSoft credential-recovery utilities, along with a notifier component that reports infection status, in some versions via the Telegram API.
The lures used business-relevant, low-friction topics: hospital surveys, blockchain project updates, project documentation, and resumes. These themes target common workflows across Human Resources, recruiting, project management, operations, and healthcare administration, where opening an attached document is routine and expected. Because the decoy document opens normally after the LNK file executes, the victim has little reason to suspect anything happened in the background.
Organizations should train employees, especially in HR, recruiting, project management, operations, and healthcare administration, to treat any "document" that actually carries a shortcut extension as suspicious and report it rather than open it. Staff should be cautious with executable files from unknown sources generally, not only attachments labeled as documents. Keeping endpoint security software updated helps reduce the chance that a malicious attachment can execute successfully even if it is opened. Encouraging a habit of reporting anything unusual after opening an attachment, even if the visible document appears normal, can help catch infections that rely on a decoy file to avoid suspicion.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Larva-24009 is a threat actor that AhnLab ASEC has tracked using phishing emails with malicious LNK files disguised as document attachments to compromise organizations.
When the LNK file is opened it runs an obfuscated PowerShell command, drops a decoy document in the TEMP folder to appear legitimate, and downloads additional malware in the background.
The campaign has used business-themed topics such as hospital surveys, blockchain, project documentation, and resumes to make the attachments seem credible.
Reported tools include QuasarRAT and UltraVNC for remote access, along with NirSoft credential-recovery utilities, screenshot capture, and keylogging, plus a notifier component that reports infection status.
You get an email from “NovaCX Recruiting” saying, “Please review the attached interview Q&A update before the next interview.” Looks harmless, right? But the attachment name is the giveaway: "NovaCX_Interview_QA+Updated_20260420_162448_version_4_4.Docx.Lnk". That “.Docx.Lnk” isn’t a real Word file, it’s a shortcut that runs hidden PowerShell, drops a fake doc, and quietly installs remote control tools. Larva-24009 loves these fake “documents” for resumes, project docs, even hospital surveys. You click, a normal-looking file opens, but in the background it’s setting scheduled tasks named things like “Intel/GoogleUpdate,” grabbing screenshots, keystrokes, and saved passwords. If you ever see an attachment ending in “.LNK” or “.Docx.Lnk,” don’t open it, hit Forward, send it to Security with one line: “Possible Larva-24009 .LNK phishing.”

Researchers reported a real spear‑phishing intrusion against a law firm where attackers sent a message with a link to an encrypted archive. The archive…

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR…

Cisco Talos reports a real campaign by a Russian-speaking group (UAT-11795) targeting users in the U.S. and Europe with trojanized installers for popular tools…

A Japanese industrial manufacturer was targeted by the SilverFox group using an invoice-themed phishing email that kicked off a multi-stage malware chain. The…

Attackers used fake Steam forum replies that looked like helpful troubleshooting steps for real gaming/PC problems. The posts tricked users into running…

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive…