[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$folZgx7-dC1rpCIPwxCHXb-49xLuUB7tnScMUX-G0EU8":3},{"article":4,"iocs":34,"watch_terms":42},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":11,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":17,"category":18,"article_tags":21},"dc07fdbf-edc7-4d5c-8c43-168462d623ad","Just seen @censysio published this article today: https:\u002F\u002Ft.co\u002Fejit3Pfxbk\nIn the Introduction, \"L...","just-seen-censysio-published-this-article-today-https-t-co-ejit3pfxbk-in-the-int","Just seen @censysio published this article today: https:\u002F\u002Ft.co\u002Fejit3Pfxbk\nIn the Introduction, \"LNK files disguised as private key folders\" &amp; the domain hui228[.]ru is mentioned.\nDoing a search for that domain here on Twitter, a month old tweet from @smica83 can be found in which https:\u002F\u002Ft.co\u002F5eBanUnIGF","Censys has published research detailing a malware campaign using LNK (shortcut) files disguised as private key folders to deceive users. The attack leverages the domain hui228[.]ru as part of its infrastructure. The campaign appears to have been active for at least a month based on related Twitter discussions.","Censys publishes research on LNK file malware disguised as private key folders using domain hui228[.]ru.",null,"https:\u002F\u002Fx.com\u002Fmalwrhunterteam\u002Fstatus\u002F2037601447429439565","2026-03-27T18:43:36+00:00","2026-03-27T19:00:11.403874+00:00",7,[],"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":17,"icon":11,"name":19,"slug":20},"Malware","malware",[22,27,29],{"category":23},{"id":24,"icon":11,"name":25,"slug":26},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":28},{"id":17,"icon":11,"name":19,"slug":20},{"category":30},{"id":31,"icon":11,"name":32,"slug":33},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[35,39],{"type":36,"value":37,"context":38},"domain","hui228[.]ru","Malware C2\u002Fdelivery domain associated with LNK file campaign",{"type":20,"value":40,"context":41},"LNK file malware (disguised as private key folders)","Social engineering attack vector using spoofed file type icons",[]]