Cisco Talos is actively tracking an ongoing campaign, targeting users in Ukraine with malicious LNK files which run a PowerShell downloader since at least November 2024.
First seen on blog.talosintelligence.com
Jump to article: blog.talosintelligence.com/gamaredon-campaign-distribute-remcos/