{"id":116995,"date":"2025-07-22T01:38:50","date_gmt":"2025-07-22T01:38:50","guid":{"rendered":"https:\/\/cybersecuritynews.com\/?p=116995"},"modified":"2025-07-22T01:38:55","modified_gmt":"2025-07-22T01:38:55","slug":"deerstealer-malware-delivered","status":"publish","type":"post","link":"https:\/\/cybersecuritynews.com\/deerstealer-malware-delivered\/","title":{"rendered":"DeerStealer Malware Delivered Via Weaponized .LNK Using LOLBin Tools"},"content":{"rendered":"\n<p>A sophisticated new phishing campaign has emerged, delivering the DeerStealer malware through weaponized .LNK shortcut files that exploit legitimate Windows binaries in a technique known as &#8220;Living off the Land&#8221; (LOLBin).<\/p>\n\n\n\n<p>The malware masquerades as a legitimate PDF document named &#8220;Report.lnk&#8221; while covertly executing a complex multi-stage attack chain that leverages mshta.exe, a legitimate Microsoft HTML Application host utility.<\/p>\n\n\n\n<p>The attack represents a significant evolution in <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> delivery mechanisms, utilizing Microsoft&#8217;s own tools to bypass traditional security measures.<\/p>\n\n\n\n<p>The malicious .LNK file initiates a carefully orchestrated execution sequence that progresses through multiple system binaries before ultimately deploying the DeerStealer payload.<\/p>\n\n\n\n<p>This approach exploits the inherent trust that security systems place in legitimate operating system components, making detection substantially more challenging.<\/p>\n\n\n\n<p>LinkedIn analysts and researchers <a href=\"https:\/\/www.linkedin.com\/posts\/any-run_deerstealer-lolbin-malware-activity-7351602552142012416-Idwp\/?utm_source=social_share_send&amp;utm_medium=member_desktop_web&amp;rcm=ACoAABO-jCkB1he5ufTfbYYMNKmaojg8M31OVpM\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this campaign as particularly concerning due to its sophisticated evasion techniques and the abuse of the MITRE ATT&amp;CK framework technique T1218.005, which specifically covers the malicious use of mshta.exe.<\/p>\n\n\n\n<p>The researchers noted that the attack&#8217;s reliance on dynamic path resolution and obfuscated command execution represents a notable advancement in malware sophistication.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Execution Chain and Infection Mechanism<\/strong><\/h2>\n\n\n\n<p>The DeerStealer infection follows a precise five-stage execution chain: .lnk \u2192 mshta.exe \u2192 cmd.exe \u2192 <a href=\"https:\/\/cybersecuritynews.com\/hackers-actively-exploiting-powershell\/\" target=\"_blank\" rel=\"noreferrer noopener\">PowerShell<\/a> \u2192 DeerStealer. <\/p>\n\n\n\n<p>The initial .LNK file covertly invokes mshta.exe to execute heavily <a href=\"https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/\" target=\"_blank\" rel=\"noreferrer noopener\">obfuscated<\/a> scripts using wildcard paths to evade signature-based detection systems.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi3EUTxIYVb12FQd_ka73wrYVxHlHbxGaZnrKhRZUB6RIhywDFjQl9S9pcjzQ48Xzd0I0ecbloxxRxQ5-INHih8y0sjjNCXd5SBWoVgvvReOyF_5ohW2W3deMM8L0j7yv3IBcQHhCEpkZnkFjPH2hTAYyh9Lm8UCPcnDlpCtO7v0HpIXwaQjFk7dbf3b48\/s16000\/DeerStealer%20Delivered%20Via%20Obfuscated%20.LNK%20Using%20LOLBin%20Abuse%20(Source%20-%20LinkedIn).webp\" alt=\"\" \/><figcaption class=\"wp-element-caption\">DeerStealer Delivered Via Obfuscated .LNK Using LOLBin Abuse (Source &#8211; LinkedIn)<\/figcaption><\/figure><\/div>\n\n\n<p>The malware dynamically resolves the full path to mshta.exe within the System32 directory, launching it with specific flags followed by obfuscated Base64 strings.<\/p>\n\n\n\n<p>To maintain stealth during execution, both logging and profiling capabilities are disabled, significantly reducing forensic visibility.<\/p>\n\n\n\n<p>The script employs a sophisticated character decoding mechanism where characters are processed in pairs, converted from hexadecimal to ASCII format, then reassembled into executable scripts via PowerShell&#8217;s IEX (Invoke-Expression) cmdlet.<\/p>\n\n\n\n<p>This ensures the malicious logic remains hidden until runtime, effectively bypassing static analysis tools.<\/p>\n\n\n\n<p>The final payload delivery involves dynamic URL resolution from obfuscated arrays, simultaneous download of a decoy PDF document to distract victims, and silent installation of the main executable into the AppData directory.<\/p>\n\n\n\n<p>The legitimate PDF opens in Adobe Acrobat as a diversion tactic while the malware establishes <a href=\"https:\/\/cybersecuritynews.com\/detecting-and-responding-to-new-nation-state-persistence-techniques\/\" target=\"_blank\" rel=\"noreferrer noopener\">persistence<\/a>.<\/p>\n\n\n\n<p>Key indicators of compromise include the domain tripplefury[.]com and SHA256 hashes fd5a2f9eed065c5767d5323b8dd928ef8724ea2edeba3e4c83e211edf9ff0160 and 8f49254064d534459b7ec60bf4e21f75284fbabfaea511268c478e15f1ed0db9.<\/p>\n\n\n\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Boost detection, reduce alert fatigue, accelerate response; all with an interactive sandbox built for security teams -&gt;\u00a0<a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=top3_ciso_challenges&amp;utm_content=demo_1&amp;utm_term=160725\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try ANY.RUN Now<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A sophisticated new phishing campaign has emerged, delivering the DeerStealer malware through weaponized .LNK shortcut files that exploit legitimate Windows binaries in a technique known as &#8220;Living off the Land&#8221; (LOLBin). The malware masquerades as a legitimate PDF document named &#8220;Report.lnk&#8221; while covertly executing a complex multi-stage attack chain that leverages mshta.exe, a legitimate Microsoft [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":116998,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiaceqyIxHOrwr65cXdBYxMKR0tXs_9bZmQYuWYAdBEr8K8NdJaj8ZCDEPrBeKWpCDq0KtrU42TOpb9VTPpYyCjAD3P3rRmoJPMXDX-UzjMBg1yfjYQ2c3aWvalH04Sqd71RAsg3BLPu0u1fVOxKqO3EI-VQsw8Vlt99JpCkeH9AElxViU7PfXSoFXAp0s\/s16000\/DeerStealer%20Malware%20Delivered%20Via%20Weaponized%20.LNK%20Using%20LOLBin%20Tools.webp","fifu_image_alt":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11,48],"tags":[149,151],"class_list":{"0":"post-116995","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-cyber-security-news","8":"category-threats","9":"tag-cyber-security","10":"tag-cyber-security-news"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.7.1 (Yoast SEO v25.7) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>DeerStealer Malware Delivered Via Weaponized .LNK Using LOLBin Tools<\/title>\n<meta name=\"description\" content=\"Phishing campaign spreads DeerStealer via LNK file \u201cReport.lnk,\u201d abusing mshta.exe (LOLBin) to bypass defenses using trusted Windows tools.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cybersecuritynews.com\/deerstealer-malware-delivered\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DeerStealer Malware Delivered Via Weaponized .LNK Using LOLBin Tools\" \/>\n<meta property=\"og:description\" content=\"Phishing campaign spreads DeerStealer via LNK file \u201cReport.lnk,\u201d abusing mshta.exe (LOLBin) to bypass defenses using trusted Windows tools.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cybersecuritynews.com\/deerstealer-malware-delivered\/\" \/>\n<meta property=\"og:site_name\" content=\"Cyber Security News\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hackingtutorialsandnews\" \/>\n<meta property=\"article:published_time\" content=\"2025-07-22T01:38:50+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-07-22T01:38:55+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiaceqyIxHOrwr65cXdBYxMKR0tXs_9bZmQYuWYAdBEr8K8NdJaj8ZCDEPrBeKWpCDq0KtrU42TOpb9VTPpYyCjAD3P3rRmoJPMXDX-UzjMBg1yfjYQ2c3aWvalH04Sqd71RAsg3BLPu0u1fVOxKqO3EI-VQsw8Vlt99JpCkeH9AElxViU7PfXSoFXAp0s\/s16000\/DeerStealer%20Malware%20Delivered%20Via%20Weaponized%20.LNK%20Using%20LOLBin%20Tools.webp\" \/><meta property=\"og:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiaceqyIxHOrwr65cXdBYxMKR0tXs_9bZmQYuWYAdBEr8K8NdJaj8ZCDEPrBeKWpCDq0KtrU42TOpb9VTPpYyCjAD3P3rRmoJPMXDX-UzjMBg1yfjYQ2c3aWvalH04Sqd71RAsg3BLPu0u1fVOxKqO3EI-VQsw8Vlt99JpCkeH9AElxViU7PfXSoFXAp0s\/s16000\/DeerStealer%20Malware%20Delivered%20Via%20Weaponized%20.LNK%20Using%20LOLBin%20Tools.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Tushar Subhra Dutta\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiaceqyIxHOrwr65cXdBYxMKR0tXs_9bZmQYuWYAdBEr8K8NdJaj8ZCDEPrBeKWpCDq0KtrU42TOpb9VTPpYyCjAD3P3rRmoJPMXDX-UzjMBg1yfjYQ2c3aWvalH04Sqd71RAsg3BLPu0u1fVOxKqO3EI-VQsw8Vlt99JpCkeH9AElxViU7PfXSoFXAp0s\/s16000\/DeerStealer%20Malware%20Delivered%20Via%20Weaponized%20.LNK%20Using%20LOLBin%20Tools.webp\" \/>\n<meta name=\"twitter:creator\" content=\"@The_Cyber_News\" \/>\n<meta name=\"twitter:site\" content=\"@The_Cyber_News\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Tushar Subhra Dutta\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"DeerStealer Malware Delivered Via Weaponized .LNK Using LOLBin Tools","description":"Phishing campaign spreads DeerStealer via LNK file \u201cReport.lnk,\u201d abusing mshta.exe (LOLBin) to bypass defenses using trusted Windows tools.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cybersecuritynews.com\/deerstealer-malware-delivered\/","og_locale":"en_US","og_type":"article","og_title":"DeerStealer Malware Delivered Via Weaponized .LNK Using LOLBin Tools","og_description":"Phishing campaign spreads DeerStealer via LNK file \u201cReport.lnk,\u201d abusing mshta.exe (LOLBin) to bypass defenses using trusted Windows tools.","og_url":"https:\/\/cybersecuritynews.com\/deerstealer-malware-delivered\/","og_site_name":"Cyber Security News","article_publisher":"https:\/\/www.facebook.com\/Hackingtutorialsandnews","article_published_time":"2025-07-22T01:38:50+00:00","article_modified_time":"2025-07-22T01:38:55+00:00","og_image":[{"url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiaceqyIxHOrwr65cXdBYxMKR0tXs_9bZmQYuWYAdBEr8K8NdJaj8ZCDEPrBeKWpCDq0KtrU42TOpb9VTPpYyCjAD3P3rRmoJPMXDX-UzjMBg1yfjYQ2c3aWvalH04Sqd71RAsg3BLPu0u1fVOxKqO3EI-VQsw8Vlt99JpCkeH9AElxViU7PfXSoFXAp0s\/s16000\/DeerStealer%20Malware%20Delivered%20Via%20Weaponized%20.LNK%20Using%20LOLBin%20Tools.webp","type":"","width":"","height":""},{"width":1600,"height":900,"url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiaceqyIxHOrwr65cXdBYxMKR0tXs_9bZmQYuWYAdBEr8K8NdJaj8ZCDEPrBeKWpCDq0KtrU42TOpb9VTPpYyCjAD3P3rRmoJPMXDX-UzjMBg1yfjYQ2c3aWvalH04Sqd71RAsg3BLPu0u1fVOxKqO3EI-VQsw8Vlt99JpCkeH9AElxViU7PfXSoFXAp0s\/s16000\/DeerStealer%20Malware%20Delivered%20Via%20Weaponized%20.LNK%20Using%20LOLBin%20Tools.webp","type":"image\/jpeg"}],"author":"Tushar Subhra Dutta","twitter_card":"summary_large_image","twitter_image":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiaceqyIxHOrwr65cXdBYxMKR0tXs_9bZmQYuWYAdBEr8K8NdJaj8ZCDEPrBeKWpCDq0KtrU42TOpb9VTPpYyCjAD3P3rRmoJPMXDX-UzjMBg1yfjYQ2c3aWvalH04Sqd71RAsg3BLPu0u1fVOxKqO3EI-VQsw8Vlt99JpCkeH9AElxViU7PfXSoFXAp0s\/s16000\/DeerStealer%20Malware%20Delivered%20Via%20Weaponized%20.LNK%20Using%20LOLBin%20Tools.webp","twitter_creator":"@The_Cyber_News","twitter_site":"@The_Cyber_News","twitter_misc":{"Written by":"Tushar Subhra Dutta","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/cybersecuritynews.com\/deerstealer-malware-delivered\/#article","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/deerstealer-malware-delivered\/"},"author":{"name":"Tushar Subhra Dutta","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/7eb7d8d026aa5dd566f134d4def5c05c"},"headline":"DeerStealer Malware Delivered Via Weaponized .LNK Using LOLBin Tools","datePublished":"2025-07-22T01:38:50+00:00","dateModified":"2025-07-22T01:38:55+00:00","mainEntityOfPage":{"@id":"https:\/\/cybersecuritynews.com\/deerstealer-malware-delivered\/"},"wordCount":442,"publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"image":{"@id":"https:\/\/cybersecuritynews.com\/deerstealer-malware-delivered\/#primaryimage"},"thumbnailUrl":"https:\/\/i2.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiaceqyIxHOrwr65cXdBYxMKR0tXs_9bZmQYuWYAdBEr8K8NdJaj8ZCDEPrBeKWpCDq0KtrU42TOpb9VTPpYyCjAD3P3rRmoJPMXDX-UzjMBg1yfjYQ2c3aWvalH04Sqd71RAsg3BLPu0u1fVOxKqO3EI-VQsw8Vlt99JpCkeH9AElxViU7PfXSoFXAp0s\/s16000\/DeerStealer%20Malware%20Delivered%20Via%20Weaponized%20.LNK%20Using%20LOLBin%20Tools.webp?w=1600&resize=1600,900&ssl=1","keywords":["cyber security","cyber security news"],"articleSection":["Cyber Security News","Threats"],"inLanguage":"en-US","copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/cybersecuritynews.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/cybersecuritynews.com\/deerstealer-malware-delivered\/","url":"https:\/\/cybersecuritynews.com\/deerstealer-malware-delivered\/","name":"DeerStealer Malware Delivered Via Weaponized .LNK Using LOLBin Tools","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cybersecuritynews.com\/deerstealer-malware-delivered\/#primaryimage"},"image":{"@id":"https:\/\/cybersecuritynews.com\/deerstealer-malware-delivered\/#primaryimage"},"thumbnailUrl":"https:\/\/i2.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiaceqyIxHOrwr65cXdBYxMKR0tXs_9bZmQYuWYAdBEr8K8NdJaj8ZCDEPrBeKWpCDq0KtrU42TOpb9VTPpYyCjAD3P3rRmoJPMXDX-UzjMBg1yfjYQ2c3aWvalH04Sqd71RAsg3BLPu0u1fVOxKqO3EI-VQsw8Vlt99JpCkeH9AElxViU7PfXSoFXAp0s\/s16000\/DeerStealer%20Malware%20Delivered%20Via%20Weaponized%20.LNK%20Using%20LOLBin%20Tools.webp?w=1600&resize=1600,900&ssl=1","datePublished":"2025-07-22T01:38:50+00:00","dateModified":"2025-07-22T01:38:55+00:00","description":"Phishing campaign spreads DeerStealer via LNK file \u201cReport.lnk,\u201d abusing mshta.exe (LOLBin) to bypass defenses using trusted Windows tools.","breadcrumb":{"@id":"https:\/\/cybersecuritynews.com\/deerstealer-malware-delivered\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cybersecuritynews.com\/deerstealer-malware-delivered\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/deerstealer-malware-delivered\/#primaryimage","url":"https:\/\/i2.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiaceqyIxHOrwr65cXdBYxMKR0tXs_9bZmQYuWYAdBEr8K8NdJaj8ZCDEPrBeKWpCDq0KtrU42TOpb9VTPpYyCjAD3P3rRmoJPMXDX-UzjMBg1yfjYQ2c3aWvalH04Sqd71RAsg3BLPu0u1fVOxKqO3EI-VQsw8Vlt99JpCkeH9AElxViU7PfXSoFXAp0s\/s16000\/DeerStealer%20Malware%20Delivered%20Via%20Weaponized%20.LNK%20Using%20LOLBin%20Tools.webp?w=1600&resize=1600,900&ssl=1","contentUrl":"https:\/\/i2.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiaceqyIxHOrwr65cXdBYxMKR0tXs_9bZmQYuWYAdBEr8K8NdJaj8ZCDEPrBeKWpCDq0KtrU42TOpb9VTPpYyCjAD3P3rRmoJPMXDX-UzjMBg1yfjYQ2c3aWvalH04Sqd71RAsg3BLPu0u1fVOxKqO3EI-VQsw8Vlt99JpCkeH9AElxViU7PfXSoFXAp0s\/s16000\/DeerStealer%20Malware%20Delivered%20Via%20Weaponized%20.LNK%20Using%20LOLBin%20Tools.webp?w=1600&resize=1600,900&ssl=1","width":"1600","height":"900"},{"@type":"BreadcrumbList","@id":"https:\/\/cybersecuritynews.com\/deerstealer-malware-delivered\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cybersecuritynews.com\/"},{"@type":"ListItem","position":2,"name":"DeerStealer Malware Delivered Via Weaponized .LNK Using LOLBin Tools"}]},{"@type":"WebSite","@id":"https:\/\/cybersecuritynews.com\/#website","url":"https:\/\/cybersecuritynews.com\/","name":"Cyber Security News","description":"World&#039;s #1 Premier Cybersecurity and Hacking News Portal","publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cybersecuritynews.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/cybersecuritynews.com\/#organization","name":"Cyber Security News","url":"https:\/\/cybersecuritynews.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/","url":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","contentUrl":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","width":200,"height":200,"caption":"Cyber Security News"},"image":{"@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hackingtutorialsandnews","https:\/\/x.com\/The_Cyber_News","https:\/\/www.linkedin.com\/company\/cybersecurity-news\/"]},{"@type":"Person","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/7eb7d8d026aa5dd566f134d4def5c05c","name":"Tushar Subhra Dutta","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f8bc0247220c7d4dea6c8b5a77d910613305ead17b13c2a7920b400435a848dd?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f8bc0247220c7d4dea6c8b5a77d910613305ead17b13c2a7920b400435a848dd?s=96&d=mm&r=g","caption":"Tushar Subhra Dutta"},"description":"Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.","url":"https:\/\/cybersecuritynews.com\/author\/tushar\/"}]}},"jetpack_featured_media_url":"https:\/\/i2.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiaceqyIxHOrwr65cXdBYxMKR0tXs_9bZmQYuWYAdBEr8K8NdJaj8ZCDEPrBeKWpCDq0KtrU42TOpb9VTPpYyCjAD3P3rRmoJPMXDX-UzjMBg1yfjYQ2c3aWvalH04Sqd71RAsg3BLPu0u1fVOxKqO3EI-VQsw8Vlt99JpCkeH9AElxViU7PfXSoFXAp0s\/s16000\/DeerStealer%20Malware%20Delivered%20Via%20Weaponized%20.LNK%20Using%20LOLBin%20Tools.webp?w=1600&resize=1600,900&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/116995","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/comments?post=116995"}],"version-history":[{"count":1,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/116995\/revisions"}],"predecessor-version":[{"id":116997,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/116995\/revisions\/116997"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media\/116998"}],"wp:attachment":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media?parent=116995"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/categories?post=116995"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/tags?post=116995"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}