Suspicious Ukraine-Themed LNK Lure Files Dropped (via file_event)

PremiumReviewedSigma · High · v1
Product
windows
Category
file_event
Author
HuntRule
Published
2026-05-16
Updated
2026-08-28

ATT&CK techniques

Initial Access → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects creation of shortcut lure files with region and messaging themed names used by the STEADY#URSA campaign for removable-media replication and social engineering against Ukrainian military targets.

Related detections9 linkedT1204.001 — drag to rearrange
TinyLoader USB Propagation via Double-Extension Executables (via file_event)
Suspicious Masqueraded Windows Update Python Script Execution
ClickFix Pastejacking via Script Interpreter Command in Run Dialog MRU (via registry_set)
Suspicious Process Execution From Recycle Bin Directory
Suspicious cscript Execution of JavaScript Spawned by PowerShell
Suspicious Removable Media Spread via My Pictures Executable (via process_creation)
Suspicious Renamed MySQL Binary Executed from Temp via ClickFix (via process_creation)
Windows ClickFix/FileFix Clipboard Phishing Leading to Suspicious mshta/powershell Command Execution
Windows Registry RunMRU Tampering with HTTP/HTTPS and Script Execution Indicators
Suspicious Ukraine-Themed LNK Lure Files Dropped (via file_event)
Pivot detection · T1204.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.