logo

Bad apps bypass Windows security alerts for six years using newly unveiled trick

ID: 1f2c2c8e-bf26-565a-89a5-07663ac6b433

STIX ID: report--1f2c2c8e-bf26-565a-89a5-07663ac6b433

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-08-06

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Elastic Security Labs disclosed multiple methods to bypass Windows SmartScreen and Smart App Control, highlighting a longstanding 'LNK Stomping' bug that causes Windows to correct malformed .LNK shortcut targets and in the process remove the Mark of the Web, allowing malicious apps to evade built-in protections. The report also describes reputation-based evasion techniques (Reputation Hijacking, Reputation Seeding, Reputation Tampering), presents evidence of samples on VirusTotal dating back six years, and recommends detection engineering and countermeasures while awaiting a potential Windows fix.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.