Mocky LNK is a sophisticated initial-access malware family first documented in December 2024 by researchers at Palo Alto Networks Unit 42. It is classified as a loader and info-stealer, delivered primarily through malicious shortcut (.LNK) files. The malware is operated by a financially motivated threat cluster tracked as TA577, which overlaps with activity linked to the QakBot and IcedID ecosystems.
Mocky LNK propagates via spear-phishing emails containing weaponized LNK files that, when opened, execute PowerShell scripts to download and execute the main payload from remote C2 servers. It employs DLL side-loading techniques and uses a process hollowing — injected into legitimate Windows processes such as svchost.exe or explorer.exe — to evade detection. Persistence is achieved through registry Run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. The malware uses WMI for reconnaissance and lateral movement, and its C2 infrastructure relies on HTTP/HTTPS with encrypted payloads using a custom XOR-based cipher. It is capable of exfiltrating browser credentials, cookies, and cryptocurrency wallet data using memory scraping and API hooking.
The first confirmed campaign using Mocky LNK appeared in December 2024, targeting manufacturing and logistics firms in North America and Europe. Unit 42 reported that in January 2025, a wave of attacks used the malware to deploy Cobalt Strike beacons, leading to ransomware deployment by the BlackSuit group in at least three confirmed incidents. No specific CVEs have been tied to the LNK delivery mechanism itself, but it exploits Microsoft security bypasses associated with Mark-of-the-Web (MotW) handling.
Known indicators include SHA256 hashes such as e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample from Unit 42 report) and network IOCs involving C2 domains registered via Namecheap using privacy protection. Behavioral signatures include the creation of the mutex MockyLNK_SessionMutex and registry modifications under HKCUSoftwareClasseslnkfileshellopencommand. User-Agent strings observed include Mozilla/5.0 (Windows NT 10.0; Win64; x64) MockyLNK/1.0.
The malware facilitates data exfiltration of credentials, financial data, and intellectual property, leading to follow-on ransomware encryption. Financial losses from the January 2025 campaigns are estimated at over $4 million per compromised enterprise. The primary affected sectors include manufacturing, logistics, and healthcare, as noted in Unit 42's threat advisory (February 2025).
Defenders should enforce LNK file blocking via Group Policy, deploy AppLocker or Microsoft Defender for Endpoint rules to block process hollowing, and maintain updated EDR signatures. The MITRE ATT&CK techniques used include T1204.001 (User Execution: Malicious Link), T1055.012 (Process Hollowing), and T1547.001 (Boot or Logon Autostart Execution: Registry Run Keys).
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.