Bad apps bypass Windows security alerts for six years using newly unveiled trick
ID: 1f2c2c8e-bf26-565a-89a5-07663ac6b433
STIX ID: report--1f2c2c8e-bf26-565a-89a5-07663ac6b433
Feed Name: The Register (Security)
Elastic Security Labs disclosed multiple methods to bypass Windows SmartScreen and Smart App Control, highlighting a longstanding 'LNK Stomping' bug that causes Windows to correct malformed .LNK shortcut targets and in the process remove the Mark of the Web, allowing malicious apps to evade built-in protections. The report also describes reputation-based evasion techniques (Reputation Hijacking, Reputation Seeding, Reputation Tampering), presents evidence of samples on VirusTotal dating back six years, and recommends detection engineering and countermeasures while awaiting a potential Windows fix.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
