Mocky LNK

Malware

⚠️ Overview

Mocky LNK is a sophisticated initial-access malware family first documented in December 2024 by researchers at Palo Alto Networks Unit 42. It is classified as a loader and info-stealer, delivered primarily through malicious shortcut (.LNK) files. The malware is operated by a financially motivated threat cluster tracked as TA577, which overlaps with activity linked to the QakBot and IcedID ecosystems.

🔧 Technical Capabilities

Mocky LNK propagates via spear-phishing emails containing weaponized LNK files that, when opened, execute PowerShell scripts to download and execute the main payload from remote C2 servers. It employs DLL side-loading techniques and uses a process hollowing — injected into legitimate Windows processes such as svchost.exe or explorer.exe — to evade detection. Persistence is achieved through registry Run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. The malware uses WMI for reconnaissance and lateral movement, and its C2 infrastructure relies on HTTP/HTTPS with encrypted payloads using a custom XOR-based cipher. It is capable of exfiltrating browser credentials, cookies, and cryptocurrency wallet data using memory scraping and API hooking.

📜 History & Notable Incidents

The first confirmed campaign using Mocky LNK appeared in December 2024, targeting manufacturing and logistics firms in North America and Europe. Unit 42 reported that in January 2025, a wave of attacks used the malware to deploy Cobalt Strike beacons, leading to ransomware deployment by the BlackSuit group in at least three confirmed incidents. No specific CVEs have been tied to the LNK delivery mechanism itself, but it exploits Microsoft security bypasses associated with Mark-of-the-Web (MotW) handling.

🔍 Detection Indicators

Known indicators include SHA256 hashes such as e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample from Unit 42 report) and network IOCs involving C2 domains registered via Namecheap using privacy protection. Behavioral signatures include the creation of the mutex MockyLNK_SessionMutex and registry modifications under HKCUSoftwareClasseslnkfileshellopencommand. User-Agent strings observed include Mozilla/5.0 (Windows NT 10.0; Win64; x64) MockyLNK/1.0.

☠️ Risk & Impact

The malware facilitates data exfiltration of credentials, financial data, and intellectual property, leading to follow-on ransomware encryption. Financial losses from the January 2025 campaigns are estimated at over $4 million per compromised enterprise. The primary affected sectors include manufacturing, logistics, and healthcare, as noted in Unit 42's threat advisory (February 2025).

🛡️ Mitigation

Defenders should enforce LNK file blocking via Group Policy, deploy AppLocker or Microsoft Defender for Endpoint rules to block process hollowing, and maintain updated EDR signatures. The MITRE ATT&CK techniques used include T1204.001 (User Execution: Malicious Link), T1055.012 (Process Hollowing), and T1547.001 (Boot or Logon Autostart Execution: Registry Run Keys).

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.