The Dangers of Embedded LNK files in Office Documents
ID: 7f50cce2-4048-5acf-8319-2ede5f78780d
STIX ID: report--7f50cce2-4048-5acf-8319-2ede5f78780d
Feed Name: Binary Defense Blog
Threat Score
The report analyzes an in-the-wild attack using Office documents with embedded .lnk files that require user interaction to execute a PowerShell payload. The technique is notable for bypassing container- or VM-based sandboxes and achieving low antivirus detection; the vendor highlights behavioral detection alerts observed during a customer compromise and warns that embedded LNKs will likely be used to evade next-generation endpoint controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
