Security researcher Wietze Beukema disclosed four techniques for manipulating Windows .LNK shortcut files so that Windows Explorer’s Properties dialog can show a benign-looking target while the shortcut actually executes a different (potentially malicious) command. The methods abuse inconsistencies in how Windows prioritizes conflicting target paths across optional LNK structures, including use of forbidden path characters (e.g., embedded double quotes), non-conforming LinkTargetIDList values that diverge from LinkInfo, and a particularly impactful approach that places the “real” execution path in EnvironmentVariableDataBlock while presenting a fake target to the user (e.g., showing invoice.pdf while executing PowerShell). This enables attackers to better conceal payload execution and command-line arguments from casual inspection, increasing the effectiveness of LNK-based initial access and social engineering.
Microsoft stated the newly presented LNK “spoofing issues” are not considered vulnerabilities (per the reporting), framing them as behavior arising from the shortcut format and Explorer’s parsing/display logic rather than a security boundary bypass. Separate coverage emphasized the broader takeaway for defenders: LNK files should be treated as untrusted due to their complex binary format and the ease with which attackers can craft deceptive shortcuts that appear legitimate in UI surfaces while launching different programs at execution time.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft Security Response Center said it would not classify the EnvironmentVariableDataBlock shortcut spoofing issue, tracked as VULN-162145, as a vulnerability. Microsoft cited required user interaction, no security boundary bypass, and existing protections such as Defender, Smart App Control, and warnings for Internet-downloaded .lnk files.
Alongside the disclosure, Beukema released the open-source 'lnk-it-up' toolkit to generate test LNK files using the newly described spoofing methods and to help detect suspicious shortcuts by comparing displayed versus executed targets.
At Wild West Hackin' Fest, researcher Wietze Beukema disclosed four techniques for crafting .LNK files that display a benign target in Windows Explorer while executing a different malicious target. The methods abuse inconsistencies in how Windows resolves conflicting shortcut target data structures.
Microsoft appears to have introduced silent changes to Windows .LNK handling in June 2025 to mitigate CVE-2025-9491, a shortcut argument-hiding issue. The flaw had reportedly been exploited by numerous state-sponsored and criminal groups.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.