Windows Shortcut (LNK) Malware Strategies
ID: ec6aac26-eb56-5db3-aa34-cfccfb35a9d5
STIX ID: report--ec6aac26-eb56-5db3-aa34-cfccfb35a9d5
Feed Name: Palo Alto Networks Unit 42
Date Published: 2025-07-02
Date Updated: 2026-04-28
Author: Haizhou Wang, Ashkan Hosseini and Ashutosh Chitwadgi
This Unit 42 report analyzes the rising abuse of Windows LNK shortcut files for malware delivery, detailing four major malicious LNK categories (exploit-based, malicious-file execution, in-argument script execution, and overlay execution), common system targets (powershell.exe, cmd.exe, rundll32.exe, etc.), overlay techniques (find/findstr, mshta, PowerShell intrinsics), exploitation variants including CVE-2010-2568, and provides representative SHA256 hashes and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
