logo

Windows Shortcut (LNK) Malware Strategies

ID: ec6aac26-eb56-5db3-aa34-cfccfb35a9d5

STIX ID: report--ec6aac26-eb56-5db3-aa34-cfccfb35a9d5

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2025-07-02

Date Updated: 2026-04-28

Author: Haizhou Wang, Ashkan Hosseini and Ashutosh Chitwadgi

...
...

This Unit 42 report analyzes the rising abuse of Windows LNK shortcut files for malware delivery, detailing four major malicious LNK categories (exploit-based, malicious-file execution, in-argument script execution, and overlay execution), common system targets (powershell.exe, cmd.exe, rundll32.exe, etc.), overlay techniques (find/findstr, mshta, PowerShell intrinsics), exploitation variants including CVE-2010-2568, and provides representative SHA256 hashes and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.