Skip to content
Malware

Malicious Windows Shortcuts Use PowerShell and Node.js to Enable Remote Code Execution

A malicious Windows shortcut is being used to turn a routine download into a full remote-code-execution foothold. The campaign begins with convincing booking-themed spam and steers victims toward a ZIP archive that conceals a booby-trapped LNK file. One click can quietly start a chain that installs...

· Jul 11, 2026 · 14 min read · 👁 3 views
Malicious Windows Shortcuts Use PowerShell and Node.js to Enable Remote Code Execution

A malicious Windows shortcut is being used to turn a routine download into a full remote-code-execution foothold.

The campaign begins with convincing booking-themed spam and steers victims toward a ZIP archive that conceals a booby-trapped LNK file.

One click can quietly start a chain that installs a backdoor and gives attackers a path to run further commands.

Instead of relying on a single malicious program, the operators combine built-in Windows tools with a legitimate Node.js runtime.

This makes activity harder to spot because PowerShell, node.exe, and standard web services can appear normal in isolation. The approach also enables persistence, encrypted communications, and delivery of additional files after the first compromise.

Analysts at LevelBlue identified the activity while investigating an alert in a customer environment.

LevelBlue said in a report shared with Cyber Security News (CSN). Their findings show a campaign designed to hide each stage until the victim has already launched the shortcut.

Contents of the archive file (Source - LevelBlue)
Contents of the archive file (Source – LevelBlue)

The exposure is significant for organizations that handle frequent external messages, particularly hotels and travel-related businesses that may expect reservation correspondence.

Researchers observed new samples daily and linked more than 400 of them to a shared machine identifier, suggesting a sustained operation rather than an isolated spam run. Early samples also appeared in comments on public discussion forums.

Malicious Windows Shortcuts Use PowerShell and Node.js

The ZIP archive contains a shortcut disguised as an image by borrowing an icon from shell32.dll. When opened, it runs a hidden PowerShell command rather than displaying a photograph.

The command uses large numbers and simple math to rebuild its next address, a trick that keeps the destination from being plainly visible in the shortcut.

Decrypted payload (Source - LevelBlue)
Decrypted payload (Source – LevelBlue)

That first script checks whether Node.js is available. If it is not, the attackers fetch a genuine Node.js package, unpack it under the user’s LocalAppData folder, then decrypt an encoded JavaScript payload. Using a trusted runtime lowers suspicion while providing the environment needed to launch the backdoor.

The JavaScript is heavily scrambled and uses a custom virtual-machine-style interpreter to process hidden instructions at runtime.

It checks for an existing dropped Node.js process, helping avoid duplicate copies, and creates a Run registry entry so it restarts when the user signs in. The process is launched detached, with its window hidden and output suppressed.

The backdoor can retrieve and run more content, including Windows executables, PowerShell, or JavaScript.

Before launching a downloaded executable, it verifies that the file resembles a valid Windows program and attempts to add an exclusion for its path in Microsoft Defender. Those actions can turn an initial shortcut click into broad control of the affected device.

Blockchain Retrieval Helps Backdoor Evade Disruption

Rather than storing a command-and-control address directly in the malware, the operators query a smart contract on the TON blockchain.

This EtherHiding method lets them change the destination without rebuilding the file, complicating blocking and takedown efforts. The backdoor then opens a WebSocket connection and uses key exchange and encryption.

Contract records revealed several previously used control domains, while payload-delivery and control servers sat behind Cloudflare.

Researchers also found recurring LNK names, including photo- and IMG-themed files, and a common MachineID value. Defenders should treat unexpected shortcut archives and booking links as suspicious, especially when they ask users to bypass download warnings.

Security teams can reduce risk by filtering or closely inspecting ZIP attachments and links from unverified senders, and by blocking unnecessary shortcut execution from email-originated files.

Monitoring for concealed PowerShell, new Node.js binaries in user folders, unusual Run registry entries, and requests to blockchain API services can help expose the chain early. Organizations should isolate affected systems and review related network activity promptly.

The campaign shows how familiar tools can be chained together to hide a serious intrusion. A harmless-looking image shortcut, a legitimate runtime, and a blockchain lookup each obscure a different part of the operation.

Prompt reporting of suspicious messages and preserving the original ZIP file can give incident responders the evidence needed to contain similar infections.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
Initial URLhxxps://share.google/YLoRYlokrW3iner8rInitial victim-access URL
Redirect URLhxxps://recordstrace[.]info/5bC6vVOeP9PI3B08Redirected delivery URL
Download URLhttps://nodejs[.]org/dist/v24.13.0/node-v24.13.0-win-x64.zipLegitimate Node.js package abused by the chain
TON API URLhttps://tonapi[.]io/v2/blockchain/accounts/0c66119f0e5635c4380441d7a79baf0c02a0ab7ea6cd78de06507fc5dc2c1a5d9/methods/getdomainSmart-contract query used to obtain C2 data
TON account ID0c66119f0e5635c4380441d7a79baf0c02a0ab7ea6cd78de06507fc5dc2c1a5d9TON smart-contract account queried by the backdoor
C2 domaintonajukbhuakpo2[.]shopC2 recorded on June 2
C2 domainzloapobikahy23[.]bondHistorical C2
C2 domainhsaertyuoang34[.]sbsHistorical C2
C2 domainamanohuguta[.]cfdHistorical C2
MachineIDwin-5r0dsv23ed0Shared identifier observed across more than 400 related samples
File patternphoto-*.png.lnkPattern used to identify related malicious LNK files
File patternIMG-*.png.lnkPattern used to identify related malicious LNK files
SHA-1 / C23d84d37393e244a76c24dfd9eebd0d20914166e6 / photobookadm[.]proRelated LNK sample and extracted C2
SHA-1 / C2a5077656e98906385bea101548b462322cd947fa / flamecube[.]infoRelated LNK sample and extracted C2
SHA-1 / C2aebce6479d7d5d0d7b59a3da020969ee465f8d36 / bigfrogs[.]infoRelated LNK sample and extracted C2
SHA-1 / C2e9488c259d1e047a0ad11d4abf1bfc442f49b992 / photobookadm[.]proRelated LNK sample and extracted C2
SHA-1 / C2d0fd605b18d8af766fb7beb94f3ef7397db4aa8a / hubsecure[.]infoRelated LNK sample and extracted C2
SHA-1 / C2ded8575d8badffea8beaa2bbfcb364901b89065d / photobookadm[.]proRelated LNK sample and extracted C2
SHA-1 / C2b6aab844ee021a684ebc236c1815e0d14ef15104 / tracerecord[.]infoRelated LNK sample and extracted C2
SHA-1 / C25daab9743a4c80415d7261d2c2b3720140890e2b / photobookadm[.]proRelated LNK sample and extracted C2
SHA-1 / C2b3cefdff102b9984748ce3a94d67a76567a92e1b / bubblekip[.]infoRelated LNK sample and extracted C2
SHA-1 / C2d6ffd15c58edac8cf0f5f829b6e248e2d933aa80 / checkphoto-bookin[.]comRelated LNK sample and extracted C2
SHA-1 / C2ee17aabe0180f62278f5bcf2ed887352ced66446 / photobookadm[.]proRelated LNK sample and extracted C2
SHA-1 / C25c21735b6a823a85730b03a71fe339082c417732 / strayweirds[.]infoRelated LNK sample and extracted C2
SHA-1 / C2399712edc298a35e2cb643353b7fcfe4327e173b / bigfrogs[.]infoRelated LNK sample and extracted C2
SHA-1 / C2fe18e053366ab393430d20d7bec523071f97fcc1 / flamecube[.]infoRelated LNK sample and extracted C2
SHA-1 / C269b570e6aa1d50e4bbd89c653eb1b97dab77f174 / photobookadm[.]proRelated LNK sample and extracted C2
SHA-1 / C25c80d4af9e9251f2303b88c51435dba09b24177a / hotelphotoadm[.]infoRelated LNK sample and extracted C2
SHA-1 / C2b33043882bf31fa05a27243240361478e88963c0 / marmoteilefinance[.]comRelated LNK sample and extracted C2
SHA-1 / C2b6457f1e62be6d8121281a74b0eb75213a849be4 / lastnight[.]infoRelated LNK sample and extracted C2
SHA-1 / C2c881d5fc0c8debcf17e869f863b50a8016674a70 / lastnight[.]infoRelated LNK sample and extracted C2
SHA-1 / C2f5161d3f01fdd1acf77ff0808b3f732d9dd3a254 / fancystraits[.]infoRelated LNK sample and extracted C2
SHA-1 / C20cae9af236ae7ebbb072b058bb65ea6ed7592aae / book-photopage[.]infoRelated LNK sample and extracted C2
SHA-1 / C218949de1c7550d93e7d58ba545c2ab9703e47d51 / jsdakksd283ksl[.]comRelated LNK sample and extracted C2
SHA-1 / C20a0378a8e1b2bcf2a6d71ee8d39572897a48ab46 / lastnight[.]infoRelated LNK sample and extracted C2
SHA-1 / C20993e576ea97208db8cd9ee651f6eb6382a6565a / photobookadm[.]proRelated LNK sample and extracted C2
SHA-1 / C218a720ebe0bc1ea1aeea9b495b419cc929c427aa / photo-pagebook[.]infoRelated LNK sample and extracted C2
SHA-1 / C227a7c5f0dcaf9ed18aa41340aa95d4d5778d7708 / keysrace[.]infoRelated LNK sample and extracted C2
SHA-1 / C24c98348b9bc57485d0624a5fc7838372566aacd7 / photobookadm[.]proRelated LNK sample and extracted C2
SHA-1 / C22f9d50d3b166a667fe6b7a05da7039a8029c79b3 / fellshow[.]infoRelated LNK sample and extracted C2
SHA-1 / C2307c3a41a56e67ff6d3026c3cd6e35b751f1eafb / lastnight[.]infoRelated LNK sample and extracted C2
SHA-1 / C22aab7ce372244d0ad882c45cc76579f570d5993b / bigfrogs[.]infoRelated LNK sample and extracted C2
SHA-1 / C28a3889be09bab729a916b97ebbfda19afef828b7 / checkphoto-bookin[.]comRelated LNK sample and extracted C2
SHA-1 / C2cb1820283981c6f32db15d4220b8b8d39da5fc9a / photobookadm[.]proRelated LNK sample and extracted C2
SHA-1 / C28f0d6abefd133bd130c6fb897c764f199a08444c / photobookadm[.]proRelated LNK sample and extracted C2
SHA-1 / C2c8f0d1447c6d3304b0f4d7e24bdd41b073f5e852 / tracerecord[.]infoRelated LNK sample and extracted C2
SHA-1 / C2625cdb454461e7e82ba9b73028ddbdcbf0b5a7ab / photobookadm[.]proRelated LNK sample and extracted C2
SHA-1 / C2aa70a6966cf3c430b768977cabdeb8aa2c2b39a3 / lightsnow[.]infoRelated LNK sample and extracted C2
SHA-1 / C22cab6043e2cf54bb1b46357798fba2d8d0d62e77 / book-photopage[.]infoRelated LNK sample and extracted C2
SHA-1 / C26a0bf6e890b24870597befcb447693a598fbd897 / hotelphotoadm[.]infoRelated LNK sample and extracted C2
SHA-1 / C285cf831025122ab3f411cd21b825eef4d6322b3d / bigfrogs[.]infoRelated LNK sample and extracted C2
SHA-1 / C2a544e8b67f0989f89b556c61fedd67a84c7b1ae6 / photobookadm[.]proRelated LNK sample and extracted C2
SHA-1 / C2b0f937a64f64d30fc341b23971ce7682ca725d9e / strayweirds[.]infoRelated LNK sample and extracted C2
SHA-1 / C2435b00e224f2e001018ed52aff2bd35706614297 / keysrace[.]infoRelated LNK sample and extracted C2
SHA-1 / C2be6494df5052cb6beffaef98a9cc063db0b9a1d4 / jsdakksd283ksl[.]comRelated LNK sample and extracted C2
SHA-1 / C2a56e3014116435cb8b928e33b16ac43f18beb733 / tracerecord[.]infoRelated LNK sample and extracted C2
SHA-1 / C20451e7e75af3c2917a38753db2642619b8f4a0fd / bookconfphoto[.]infoRelated LNK sample and extracted C2
SHA-1 / C27e05edb4a326c6b80ca937d602d43590bb73d68c / fancystraits[.]infoRelated LNK sample and extracted C2
SHA-1 / C2f277f060ffcd3fbf34bb98884c8a9fa3f0f57845 / lastnight[.]infoRelated LNK sample and extracted C2
SHA-1 / C2db68cbf2359df9835a9f85b29ec01e750e814e8b / book-imagegallery[.]infoRelated LNK sample and extracted C2
SHA-1 / C2828f62be77939b3c738b6fcf43c2d308b59481f6 / deracefight[.]infoRelated LNK sample and extracted C2
SHA-1 / C20ddc606b48c4dd85cad09ffcb2fe560f68e63868 / deracefight[.]infoRelated LNK sample and extracted C2
SHA-1 / C2b8d6bb8bf3291fdb3424abbf237f191c9db67a7c / lastnight[.]infoRelated LNK sample and extracted C2
SHA-1 / C254740686b96e9702cc376d6b04f89105d7700408 / bigfrogs[.]infoRelated LNK sample and extracted C2
SHA-1 / C24d901d5bd6c467f4bedfb0b968eb4c42902cf588 / keysrace[.]infoRelated LNK sample and extracted C2
SHA-1 / C2d807a3f8dff4f9b8dc828b3e0ef56f85534a91d8 / lastnight[.]infoRelated LNK sample and extracted C2
SHA-1 / C2b9205e4cc92be77dfd4c8767f86384a36520e331 / dsjkaksfks324das[.]comRelated LNK sample and extracted C2
SHA-1 / C2b196b2552a18b8112b72ed7aab4e8ddb1253a81e / tracerecord[.]infoRelated LNK sample and extracted C2
SHA-1 / C211838c2e3134991402e40a1744aa4c1f93447407 / photobookadm[.]proRelated LNK sample and extracted C2
SHA-1 / C2b82652f33d382a96d9ab5f60dc7a6897dd0f5dfd / photo-pagebook[.]infoRelated LNK sample and extracted C2
SHA-1 / C2fb9e1728a0017321fd74f6f9b860b1d5af05d392 / photo-26654[.]cfdRelated LNK sample and extracted C2
SHA-1 / C25a944255ee92ba70654d6ed73a52b5de22942340 / hotelphotoadm[.]infoRelated LNK sample and extracted C2
SHA-1 / C27ae18cb6532f2ebb0b6231509541118b52583dc0 / photobookadm[.]proRelated LNK sample and extracted C2
SHA-1 / C2e924650b4fb36679243e7e511fe8e1b00ab2fe6b / checkphoto-bookin[.]comRelated LNK sample and extracted C2
SHA-1 / C2717e816d99377e285f894457d7a662d85f39053f / fancystraits[.]infoRelated LNK sample and extracted C2
SHA-1 / C2b255bda9419d919501ae89fadab3ba54e5c0e86b / lastnight[.]infoRelated LNK sample and extracted C2
SHA-1 / C265b2a34be17b3d31221d55f9829f7d876634eaed / tracerecord[.]infoRelated LNK sample and extracted C2
SHA-1 / C217abeb78bb862d702d4e63d746c58d2d805d71ee / haddjskak827sja[.]comRelated LNK sample and extracted C2
SHA-1 / C233f6d432464c20bbdf019f62510435e9a45e29bc / photo-27657[.]cfdRelated LNK sample and extracted C2
SHA-1 / C211b2f77a7abf1593648bbcc5bdeb27c4f890aef3 / photo-26654[.]cfdRelated LNK sample and extracted C2
SHA-1 / C24e3baea41d73967aac96b3cb6525b9edb0ccacd8 / strayweirds[.]infoRelated LNK sample and extracted C2
SHA-1 / C2e086583b8bd11a5a146e522f5ac8d8ac68111f44 / photo-26654[.]cfdRelated LNK sample and extracted C2
SHA-1 / C2932f4b274e6f08c55b64a4e7a0cbbe9dff829649 / tracerecord[.]infoRelated LNK sample and extracted C2
SHA-1 / C20b6e6d9c0091b1f8580bee455eb2199a4fe8a7e0 / photobookadm[.]proRelated LNK sample and extracted C2
SHA-1 / C2206810a3effe5e477ffc441731b58f7f6cd2c04b / checkphoto-bookin[.]comRelated LNK sample and extracted C2
SHA-1 / C2b75d84cc997bfcc8e0f03b091e067a74030b29ce / photo-62454[.]cfdRelated LNK sample and extracted C2
SHA-1 / C27ba0659c3c33ff97a3c8e10a304b26a58f450b4e / flamecube[.]infoRelated LNK sample and extracted C2
SHA-1 / C2954a7dc750ac502c51dfd7db2068a11961b2f342 / lastnight[.]infoRelated LNK sample and extracted C2
SHA-1 / C2c45a08b8bfa12241865dc82b417a29dbc2510a54 / confbookphoto[.]infoRelated LNK sample and extracted C2
SHA-1 / C26145aabf54337e633670aa2e82835fae97612a5d / aboutbookphoto[.]proRelated LNK sample and extracted C2
SHA-1 / C24edec9cff71c5467808c0a919ba05f13489d21ab / ancamp[.]infoRelated LNK sample and extracted C2
SHA-1 / C2df5197155515d5f706ecb9b2b326e11d9ed215ed / photobookadm[.]proRelated LNK sample and extracted C2
SHA-1 / C2efd4283b06ae8a9555475f91f59a733b7b73ddfa / book-imagegallery[.]infoRelated LNK sample and extracted C2
SHA-1 / C227e1eeb34bd8bd4b54760f15c88dd33f58507e09 / lastnight[.]infoRelated LNK sample and extracted C2
SHA-1 / C2391485c342138e8d137d88f927423eb5d7c00ad6 / vault-docs-x[.]infoRelated LNK sample and extracted C2
SHA-1 / C25edc16ff32ff12ee2bf0abbc85a62b93eddab3b3 / photobookadm[.]proRelated LNK sample and extracted C2
SHA-1 / C2a47ce3551596100173879d406d75b5f960d25c02 / photohotels-visit[.]cloudRelated LNK sample and extracted C2
SHA-1 / C2194fb8cbab8b030944e9a1ec44f2e4383f394589 / replyjoke[.]infoRelated LNK sample and extracted C2
SHA-1 / C2bd80fa9a88e0b201dbd0e1814d5884c6ac011e5b / photo-26656[.]cfdRelated LNK sample and extracted C2
SHA-1 / C20d9796ccb481b09bd92bbe1d7719d0939f645514 / photo-132454[.]cfdRelated LNK sample and extracted C2
SHA-1 / C28e0e6e3ef3adf32db8ab3826377e0da7e8adb815 / photo-26653[.]cfdRelated LNK sample and extracted C2
SHA-1 / C2e792d6b848af9ed81d98a15b2d2fc5c80eba321a / lightsnow[.]infoRelated LNK sample and extracted C2
SHA-1 / C29dd1ff00c45da21a2eb57f612f7da5dfe57738f0 / photo-27657[.]cfdRelated LNK sample and extracted C2
SHA-1 / C2582cd134c017435b027a2fea86f4e584d69a214f / photobookadm[.]proRelated LNK sample and extracted C2
SHA-1 / C29b7fcaed4634dd918a26352f12a26f04c52be3a1 / safegallery[.]infoRelated LNK sample and extracted C2
SHA-1 / C23c908051cdef94e60b6f444e8719d291a57a2941 / marmoteilefinance[.]comRelated LNK sample and extracted C2
SHA-1 / C242b40f25d025f23e42aa44f98466ce08bf022f26 / photobookadm[.]proRelated LNK sample and extracted C2
SHA-1 / C25a14c0a131c4e5a729a28556b119876651a4047f / photobookadm[.]proRelated LNK sample and extracted C2
SHA-1 / C26f171cc3fe263ff8257c4a8cc38b1cf71fd46343 / photobookadm[.]proRelated LNK sample and extracted C2
SHA-1 / C237b61fb43cf3aee0c0c6b3347abd018fc5eb0a5c / photobookadm[.]proRelated LNK sample and extracted C2
SHA-1 / C20225c25e9e7462a80ec157c76e2479487c8508bd / checkphoto-bookin[.]comRelated LNK sample and extracted C2

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Related Articles

Recommended for you