← Back to Feed

Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor

July 9, 2026 · LevelBlue SpiderLabs · Severity: HIGH

A multi-stage attack leveraging malicious LNK files and the TON blockchain was discovered by LevelBlue SpiderLabs. The attack begins with a ZIP file containing a Windows shortcut (LNK) that executes a hidden PowerShell command to download a legitimate Node.js binary, which then deploys a backdoor. The malware uses EtherHiding, a technique that retrieves command-and-control (C2) addresses from the TON blockchain, making detection harder. This attack targets Windows users who unknowingly execute the malicious LNK file, leading to a stealthy Node.js-based backdoor infection. The use of blockchain for C2 communication complicates tracking and mitigation efforts. Organizations should scrutinize unexpected ZIP and LNK files and monitor for unusual Node.js activity to defend against similar threats.

The LevelBlue Managed Threat Research team investigated a security alert in a customer environment involving a malicious ZIP file containing a Windows shortcut (.lnk) used for initial execution. When triggered, the LNK file executes a hidden PowerShell command that downloads a legitimate node.exe binary and deploys a NodeJS-based backdoor. The malware also uses the EtherHiding technique, leveraging the TON blockchain to retrieve its command-and-control (C2) address.

Key Takeaways

  • Multi-stage LNK attack uses TON blockchain for delivery.
  • Malicious ZIP files execute PowerShell to download Node.js backdoor.
  • Leveraging blockchain adds stealth to the attack chain.
☕ Buy a Coffee