

LNK Leads to DARTHVADER Stealer via LOLBins and AutoIt.
A malicious LNK disguised as a PDF launches a multi-stage chain with cmd.exe, LOLBins, AutoIt, and PowerShell, leading to stealer deployment and persistence. The risk is post-click compromise.
Observed behavior: hidden command execution with disabled output, curl.exe downloads, PowerShell ExecutionPolicy Bypass, mutex creation, and persistence setup.
cmd.exe /V:ON enables delayed environment variable expansion, while /D disables execution of AutoRun commands. Fewer artifacts make the chain harder to trace and can delay containment.
See the execution chain and collect IOCs to speed up detection & response: https://app.any.run/tasks/81e896a9-849b-491f-8dc4-edd51fed632b/