A newly discovered campaign targets individuals and organizations in Ukraine by utilizing document-themed Windows shortcuts to install a malware downloader named VelvetCake This article explores malicious shortcuts seemingly. . This distinction is significant because the observed malware can gather system details, capture screens, and send files from an infected machine.

The malicious PDFs, which are actually Windows shortcut files (LNK files) disguised as documents, contain topics such as a proposed peace framework for Russia-Ukraine, rising food prices due to the Strait of Hormuz, and a social researcher's resume. No victim list was disclosed. Another script delivers VelvetCake, a small downloader that connects to an attacker-controlled server, retrieves available scripts, runs them, and sends back any resulting files.

The chain bears resemblance to Kim'sky attacks using malicious shortcuts, where a seemingly harmless document initiates a longer infection. One recovered follow-on script checked installed security software, system settings, network configuration, running processes, recent files, and available drives. VelvetCake's code snippets (Source – SOCRadar) It also took a screenshot and sent the gathered data to an external server before deleting local copies.

Before opening attachments, check their file type, watch for unusual scheduled tasks, and review PowerShell activity to detect potential infections. As demonstrated by earlier Konni phishing campaigns, a familiar document theme can conceal the first step of a much larger intrusion. The URL hxxp://p1o2i3u4y5t6r7e8w9q0.medianewsonline.com/login.php?OKey=env:userdomain&Areyou=cake&Who=env:username initiates a remote-code request.