Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
remote-access-implantinitial-access-methodcommand-and-control-methodpersistence-method

LNK-Based Malware Campaigns Deliver PlugX and Custom .NET RAT

Updated 2mo agoFirst seen Apr 9, 20262 sources

Researchers documented two separate but related LNK-driven intrusion chains that used shortcut files as the initial lure to fetch additional malware from attacker-controlled infrastructure. In one campaign targeting organizations in the Arabian Gulf region, a China-nexus threat actor used a Middle East conflict-themed ZIP archive containing an LNK file that downloaded a malicious CHM file and ultimately deployed a PlugX backdoor. The infection chain progressed through a second LNK, a TAR archive, DLL sideloading, and a shellcode loader before installing PlugX with persistence under a fake Microsoft Display Broker path and service name. The malware used RC4-encrypted components, API hooking, reflective DLL loading, corrupted PE headers, and support for TCP, HTTPS, UDP, and DoH communications, with a decrypted command-and-control endpoint at 91.193.17[.]117:443 and plugins for keylogging, shell access, screen capture, registry, service, and network operations.

A second investigation exposed a live LNK-to-DLL-to-.NET RAT operation staged from an open Apache directory on wildishadventure[.]com/secure9/ and 171.22.182[.]231/secure9/, where researchers recovered weaponized LNK files, custom DLL downloaders, backup files, and a final payload named RemoteMgmt.Agent.exe. That chain abused the legacy ActiveXObject('htmlfile') technique to force Windows to retrieve DLLs over UNC paths, then delivered a custom .NET 4.8 remote access trojan that supported command execution, token-based authentication, JSON-over-raw-TCP C2 over port 443, reconnect-based persistence, and logging to %TEMP%\rmgmt_agent.log. Operational security failures including exposed directory indexing, .old backups, test builds, and unstripped internal names allowed investigators to reconstruct the malware’s development workflow and identify infrastructure spanning BlueVPS, Namecheap, and Cloudflare.

Share:
LNK-Based Malware Campaigns Deliver PlugX and Custom .NET RAT
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Apr 2, 20263mo ago

Researchers uncover exposed open directory with live multi-stage RAT campaign

By April 2, 2026, investigators had uncovered an open Apache directory at wildishadventure[.]com/secure9/ and 171.22.182[.]231/secure9/ exposing weaponized LNK files, custom DLL downloaders, backups, and a live .NET RAT payload. The exposed files and infrastructure let researchers reconstruct the full attack chain and recover indicators of compromise.

Mar 24, 20263mo ago

Attackers begin active development of BlueVPS-hosted LNK-to-RAT chain

Evidence from exposed infrastructure showed the LNK-to-DLL-to-.NET RAT malware stack was actively developed between March 24 and April 1, 2026. Researchers found test builds, backup files, and related components indicating iterative development and staging on BlueVPS and associated hosting.

Mar 1, 20264mo ago

Threat actor launches PlugX attack themed on Middle East conflict

On March 1, 2026, ThreatLabz identified an attack chain targeting the Arabian Gulf region that used a ZIP archive with an LNK file, a malicious CHM, and subsequent stages to deploy a PlugX backdoor variant. The lure included an Arabic decoy PDF referencing Iranian missile strikes against a U.S. base in Bahrain.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
Malware
1 linked
Organizations
5 linked
ZscalerBaiduBitdefenderGoogle360 Print Solutions
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.