logo

Rise of LNK (Shortcut files) Malware

ID: 49d7dbb0-a1fe-5a58-b7b1-23f1e79d1963

STIX ID: report--49d7dbb0-a1fe-5a58-b7b1-23f1e79d1963

Feed Name: McAfee Labs Blog

Threat Score
75/100

Date Published: 2022-06-21

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

This McAfee Labs analysis documents a rise in malicious Windows LNK (shortcut) files used to deliver Emotet, IcedID, and Qakbot via email and malicious URLs; it details infection chains where LNKs invoke cmd.exe, PowerShell, MSHTA and other Windows utilities to write and execute staged payloads, and provides technical indicators (SHA-256 hashes and URLs) and detection labels for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.