{"id":11459,"date":"2025-07-22T12:31:49","date_gmt":"2025-07-22T05:31:49","guid":{"rendered":"https:\/\/infosec.new88088.net\/?p=11459"},"modified":"2026-06-25T09:59:46","modified_gmt":"2026-06-25T02:59:46","slug":"deerstealer-malware-campaign-when-harmless-file-shortcuts-become-data-steal-tools","status":"publish","type":"post","link":"https:\/\/infosec.new88088.net\/en\/2025\/07\/22\/deerstealer-malware-campaign-when-harmless-file-shortcuts-become-data-steal-tools\/","title":{"rendered":"DeerStealer malware campaign: When harmless file shortcuts become data steal tools"},"content":{"rendered":"<div style=\"text-align: justify\"><b>A new cyberattack operation has been discovered by cybersecurity experts, using a seemingly harmless Windows shortcut file (.LNK ), to spread malicious information theft <b>DeerStealer<\/b>. The campaign was not only technically sophisticated but also hit a major flaw in user behavior, the habit of opening files of &#8220;reports,&#8221; &#8220;orders,&#8221; or &#8220;invoices&#8221; that are emailed without scrutiny.<\/b><br \/>\n\u200b<\/div>\n<div style=\"text-align: center\">\n<div class=\"bbImageWrapper js-lbImage\" title=\"1753175199674.png\" data-lb-caption-extra-html=\"\" data-lb-sidebar-href=\"\" data-single-image=\"1\" data-src=\"https:\/\/whitehat.vn\/attachments\/1753175199674-png.17352\/\"><img fetchpriority=\"high\" decoding=\"async\" class=\"bbImage\" title=\"1753175199674.png\" src=\"https:\/\/whitehat.vn\/attachments\/1753175199674-png.17352\/\" alt=\"1753175199674.png\" width=\"692\" height=\"360\" data-url=\"\" data-zoom-target=\"1\" \/><\/div>\n<\/div>\n<div style=\"text-align: justify\">\n<p>No specific attack group has claimed responsibility for the DeerStealer dispersal campaign. However, the sophistication of the techniques used suggests that this is a well-thought-out, deliberate campaign and aimed at individuals or organizations that own sensitive data, such as: Social media accounts, digital wallets, email accounts, or company-wide data.<\/p>\n<p>The attack begins with a shortcut file called &#8220;Report.lnk&#8221; which is disguised as a report or document. When clicked, the file silently activates an existing Windows tool called &#8220;mshta.exe&#8221; (which runs HTML applications) to execute hidden malicious code.<\/p>\n<p>This process doesn&#8217;t stop there. Mshta launches &#8220;cmd.exe&#8221; and then PowerShell, where a series of malicious code is decrypted step by step from Base64 encryption. Scripts were even designed to disable PowerShell&#8217;s logging and behavioral tracking, making detection nearly impossible with conventional security tools.<\/p>\n<p>One of the most sophisticated user tricks of this campaign is that as soon as you open the &#8220;.LNK&#8221; file, a fake PDF will be downloaded and opened in Adobe Reader. While the user was viewing the document, DeerStealer malicious code was silently written to the% AppData% directory and activated in the background.<\/p>\n<p>Malicious code download addresses are created from scrambled character sequences, which helps them avoid IOC (Indicators of Compromise) index-based filtering tools. The malicious code even tests the exact location of mshta.exe on each infected machine rather than using a fixed path, making detection even more difficult.<\/p>\n<p>Researchers from the malicious code analysis platform &#8220;ANY.RUN&#8221; tracked the entire attack sequence in real time and said:<\/p>\n<\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">The campaign uses multiple layers of encryption and &#8220;system &#8211; based survival&#8221; (LOLBin) techniques such as mshta.exe, PowerShell<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">The malicious code can adjust its behavior depending on the environment to avoid detection<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Scalability rapidly if automated via email spam or phishing tools<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">\n<p>For both personal and business users, it&#8217;s time to take extra precautions with any &#8220;.LNK&#8221; attachment, even if the file name sounds &#8220;reasonable&#8221; such as &#8220;report&#8221;, &#8220;invoice&#8221;, or &#8220;contract&#8221;.<\/p>\n<p>Recommendations:<\/p>\n<\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Warn users not to open unfamiliar.LNK,.zip,.exe files, especially via email.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Enhanced monitoring of PowerShell behavior, mshta.exe, and unusual shortcuts by EDR, Sysmon, or Wazuh.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Update the IOC and new attack techniques to SIEM for early detection, especially for indexes related to DeerStealer.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Restrict your ability to create Scheduled Task, monitor the Registry Run to reduce the likelihood of malware crashes.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Turn off or limit mshta.exe if not necessary<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Update your antivirus software and enable behavioral analysis<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">For businesses, it&#8217;s recommended to implement a real-time monitoring and deep checks of PowerShell operations in the internal system<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Provides internal training on malicious shortcut file identification and modern deceptive techniques.<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">This form of attack is difficult to detect and has serious consequences, being a clear reminder that a compact file such as &#8220;.LNK&#8221; can also be a gateway for hackers to enter and steal entire personal or business data. In a world where malware is increasingly sophisticated, every click must be accompanied by vigilance.<\/div>\n<div style=\"text-align: right\"><b><i>WhiteHat<\/i><\/b>\u200b<\/div>\n<div style=\"text-align: right;margin-top: 16px\"><i>Theo: <a href=\"https:\/\/whitehat.vn\/threads\/chien-dich-ma-doc-deerstealer-khi-tep-shortcut-vo-hai-tro-thanh-cong-cu-danh-cap-du-lieu.18590\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/whitehat.vn\/threads\/chien-dich-ma-doc-deerstealer-khi-tep-shortcut-vo-hai-tro-thanh-cong-cu-danh-cap-du-lieu.18590\/<\/a><\/i><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A new cyberattack operation has been discovered by cybersecurity experts, using a seemingly harmless Windows shortcut file (.LNK ), to spread malicious information theft DeerStealer. The campaign was not only technically sophisticated but also hit a major flaw in user behavior, the habit of opening files of &#8220;reports,&#8221; &#8220;orders,&#8221; or &#8220;invoices&#8221; that are emailed without [&hellip;]<\/p>\n","protected":false},"author":46,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[351],"tags":[],"class_list":["post-11459","post","type-post","status-publish","format-standard","hentry","category-news-announcements"],"_links":{"self":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11459","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/comments?post=11459"}],"version-history":[{"count":2,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11459\/revisions"}],"predecessor-version":[{"id":11647,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11459\/revisions\/11647"}],"wp:attachment":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/media?parent=11459"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/categories?post=11459"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/tags?post=11459"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}