Threat actors are increasingly abusing Windows shortcut files (.LNK) as a low-friction mechanism for initial access, payload execution, and persistence across phishing and archive-based intrusion chains. Multiple reports describe attackers disguising LNKs as PDFs, resumes, project files, or document shortcuts inside ZIP, RAR, ISO, and IMG containers, then using them to launch LOLBins and scripts such as powershell.exe, mshta.exe, regsvr32.exe, rundll32.exe, cmd.exe, and MSBuild.exe. Campaigns tied to QakBot, Emotet, Bumblebee, MORE_EGGS, Gamaredon, APT37, Higaisa, and likely APT41/Winnti used LNK-triggered chains to download payloads, execute JavaScript or PowerShell, establish scheduled-task or Startup-folder persistence, and deploy stealers, RATs, and backdoors. Researchers note the trend accelerated after Microsoft blocked internet-downloaded Office macros by default, pushing operators toward shortcut-based delivery.
Defenders are being urged to inspect the LNK Target field and underlying Shell Link structures for suspicious command lines, embedded URLs or IPs, oversized files, and metadata anomalies such as mismatched TrackerDataBlock MAC information. Microsoft’s Shell Link specification provides the file-format baseline, while incident-response guidance highlights that explorer.exe often appears as the parent process, making file telemetry and LNK creation events critical for hunting. Analysts also point to builder ecosystems such as mLNK Builder that lower the barrier for criminal use and improve evasion, alongside older LNK-related exploitation history including CVE-2010-2568, which allowed code execution when Windows rendered crafted shortcut icons. Together, the reporting shows .LNK files have become a durable and versatile attack primitive spanning commodity malware, espionage operations, and persistence tradecraft.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
22 events from the most recent confirmed update back to the earliest known activity.
Resecurity reported on mLNK Builder, a dark web tool for generating malicious .LNK files, and said version 4.2 introduced improved antivirus evasion and masquerading features. The report linked LNK-based delivery to malware families and campaigns including Bumblebee, Qakbot, IcedID, AsyncRAT, Emotet, Matanbuchus, and UAC-0010 activity.
Zscaler published research correlating a May 2020 LNK-based malware campaign to the South Korean APT actor Higaisa with moderate confidence. The report cited code overlap, similar TTPs, shared backdoor traits, common LNK SID metadata, and infrastructure links.
Intezer published an analysis explaining how threat actors increasingly abuse LNK files for initial access and execution, especially after Microsoft blocked internet-downloaded Office macros by default. The article highlighted examples including Emotet, Bumblebee, Qakbot, and Quantum tooling, along with detection indicators for suspicious shortcuts.
Microsoft published major revision 10.0 of the Shell Link (.LNK) binary file format specification.
Microsoft published revision 9.0 of the Shell Link (.LNK) binary file format specification.
Cyble Research and Intelligence Labs identified a malware campaign using a ZIP archive containing a PDF-disguised LNK and an XML file masquerading as a PNG. The LNK created a scheduled task named Darkmoon_Gaming to run MSBuild.exe every 15 minutes, enabling fileless execution and later Chrome data theft via Telegram-controlled malware.
Securonix reported the ongoing SHROUDED#SLEEP campaign and likely attributed it to North Korea's APT37. The intrusion chain used phishing-delivered ZIP archives containing deceptive .lnk files, Startup-folder persistence, AppDomainManager hijacking, and the VeilShell PowerShell backdoor against Southeast Asian targets.
Microsoft published major revision 8.0 of the Shell Link (.LNK) binary file format specification.
A technical walkthrough demonstrated creating a Windows shortcut with a programmed hotkey such as CTRL+W that launches a payload when pressed. The proof of concept used PowerShell and the Wscript.Shell COM object to generate a desktop LNK file for persistence and execution.
Cisco Talos reported an ongoing Gamaredon espionage campaign targeting Ukrainian entities with phishing lures themed around the Russian invasion. Office documents with remote-template VBScript macros downloaded RAR archives containing LNK files that invoked mshta.exe and PowerShell to fetch additional payloads.
Expel observed a phishing attack against a recruiter in which a fake resume workflow delivered a ZIP archive that created a malicious LNK file. The shortcut launched obfuscated commands and abused regsvr32, wmic, ie4uinit.exe, and msxsl.exe, with behavior assessed as consistent with MORE_EGGS.
By 2022, QakBot operators had started using .LNK files instead of their more traditional XLS-based delivery method. The described chain used HTML and ZIP files to deliver a shortcut that launched commands involving msedge.exe, ping, curl.exe, a malicious .dat file, and regsvr32.exe.
Positive Technologies disclosed a series of attacks attributed to Winnti/APT41 targeting organizations in Russia and Hong Kong. The reporting tied the activity to Crosswalk, FunnySwitch, and overlapping infrastructure previously associated with APT41.
A second attack in the Winnti/APT41 campaign was detected on May 30, 2020 using a malicious RAR archive containing shortcuts to bait curriculum vitae and IELTS certificate PDFs. The chain retrieved final-stage malware from Zeplin-hosted links and included svchast.exe and the Crosswalk backdoor.
Positive Technologies dated the first observed attack in a campaign attributed to Winnti/APT41 to May 12, 2020. That intrusion used LNK shortcut files to extract and execute malware payloads against targets in Russia and Hong Kong.
Researchers observed several malicious LNK files in May 2020 that were later attributed with moderate confidence to Higaisa. The campaign used RAR-delivered shortcut files with Zeplin and document decoys to target users of Chinese origin and deploy a backdoor via svchast.exe.
Trend Micro reported a malicious LNK-file-based threat detected in Israeli hospitals and further classified it as the RETADUP backdoor worm. The malware propagated using shortcut files, a legitimate AutoIt executable, and encrypted payloads while stealing credentials, logging keystrokes, and spreading through drives and shared folders.
Microsoft released version 1.0 of its Open Specifications documentation for the Shell Link (.LNK) binary file format, defining the format used by Windows shortcut files.
A Windows Shell vulnerability in shortcut file handling, CVE-2010-2568, was exploited in the wild in July 2010, allowing arbitrary code execution via crafted .LNK or .PIF files when Explorer displayed their icons. The sample discussed was associated with Win32/Chymine.A and downloaded a keystroke logger.
A follow-up analysis of a malicious LNK sample showed its Target field launched PowerShell with a Base64-encoded payload obfuscated with caret characters. After decoding, the recovered command invoked mshta to retrieve content from a gofile.io URL masquerading as an MP4 file and execute it via iex.
A technical explainer outlined how attackers abuse LNK files to download additional malware stages, run cloud-hosted scripts, or directly execute malicious scripts. It also recommended inspecting the target field manually or extracting metadata with LnkParse3.
Cybereason published a threat analysis describing increased malware delivery through LNK files after Microsoft changed handling of internet-downloaded macro-enabled files. The report demonstrated LNK use as downloaders, Startup-folder persistence, and hidden-file launchers, and reviewed campaigns involving Astaroth, Qbot, IcedID, and Yellow Cockatoo.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
16 references tracked. Mallory keeps watching after this page renders.
intezer.com
Open sourcezscaler.com
Open sourceresecurity.com
Open sourcelearn.microsoft.com
Open sourceblog.trendmicro.com
Open sourcecontagiodump.blogspot.com
Open sourcereversethemalware.blogspot.com
Open sourcecybereason.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.