Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Chollima APT Hackers Weaponize LNK File to Deploy Sophisticated Malware

The Ricochet Chollima advanced persistent threat group initiated a targeted campaign against activists and organizations focusing on North Korea in March 2025.

The Ricochet Chollima advanced persistent threat group initiated a targeted campaign against activists and organizations focusing on North Korea in March 2025.

The operation, termed "Operation: ToyBox Story" by Genians Security Center, employs a combination of social engineering and malware delivery tactics.

Attackers distribute spear-phishing emails impersonating North Korea-focused security experts. These emails include Dropbox links to compressed archives containing malicious Windows shortcut files. Victims inadvertently download files that execute hidden code upon opening.

The attack is sophisticated, using culturally relevant email subject lines and Hangul document icons to increase engagement and disguise the malicious content.

This approach relies on social engineering, exploiting users' trust in familiar file icons and organizations.

The operation, termed "Operation: ToyBox Story" by Genians Security Center, employs a combination of social engineering and malware delivery tactics.
Zachary Burns · Thehackingpost

An Offensive Security Engineer, S3N4T0R, analyzed the campaign and identified the malware's progression through multiple stages, designed to evade security tools and maintain persistence.

Fileless Execution Through Memory Injection

The malware's key threat is its fileless execution capability, which leaves no traces on the hard drive. A hidden PowerShell command within the shortcut executes silently when the ZIP archive is extracted and the document file is opened.

This command triggers a batch file named "toy03.bat," which loads "toy02.dat" from the temporary folder. The loader decodes XOR-transformed data and injects shellcode directly into memory, bypassing traditional detection methods.

Once in memory, the malware creates a new executable thread to run the injected code. This fileless malware execution technique poses significant challenges for security teams, as it leaves minimal evidence on disk.

Advertisement

The malware then communicates via Dropbox API channels, allowing attackers to send commands and receive stolen data while concealing activities within legitimate cloud service traffic.

This technique represents a significant advancement in APT tactics, utilizing trusted services to obscure malicious operations and complicate detection efforts for defenders.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories