Install agent persistence via .LNK file

APT40 is known to use .LNK files in the Windows StartUp folder for persistence. This procedure generates a link file using VBA and executes it. On startup, the link will execute a Pneuma agent.
View Command

To view this TTPs command, you must be logged in with a professional or enterprise license.


Test this TTP

Download Operator (1.7.1)
Test this TTP using one of our Operator chains
APT40 maritime industry


Emulating APT40's malware persistence techniques.