Threat actors increasingly replaced macro-enabled Office documents with Windows shortcut (.LNK) files, ISO images, and HTML smuggling to gain initial access on Windows systems after Microsoft tightened macro protections and as adversaries sought ways around Mark-of-the-Web controls, including CVE-2022-41049. Fortinet reported phishing campaigns in 2022 delivering Emotet, Qbot/QakBot, IcedID, and Bumblebee through Excel 4.0 macros early on, then shifting to LNK files, ISO containers, and browser-reconstructed payloads that launched malware via native tools such as
powershell
mshta.exe
regsvr32.exe
rundll32.exe
curl
cmd.exe
A separate Fortinet investigation detailed a QakBot campaign in which an attached HTML file dropped a ZIP archive containing a malicious LNK that fetched a loader DLL and executed the core malware filelessly inside a hollowed process.
Cisco Talos found that the growing use of malicious LNK files also created a forensic trail: embedded metadata such as Drive Serial Number, MachineID, DROID GUIDs, timestamps, paths, and SIDs can link campaigns and expose the systems used to build the shortcuts. Talos used Qakbot and Gamaredon examples to show how LNK metadata supports clustering and hunting, and identified metadata-based ties between Bumblebee, IcedID, and Qakbot, suggesting shared tooling or operational overlap. Earlier Fortinet reporting showed LNK-based phishing was already being used in espionage operations, including a campaign targeting Ukrainian government entities with ZIP archives containing malicious shortcuts, reinforcing that LNK files had become a versatile delivery mechanism for both financially motivated malware and state-linked intrusion activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
22 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos published research showing how metadata embedded in malicious Windows LNK files can be used to cluster campaigns, track operators, and reveal links between malware ecosystems. The report also described metadata-based relationships connecting Bumblebee with IcedID and Qakbot.
Cisco Talos said a later spike in LNK-file usage around October and November 2022 may have been influenced by vulnerabilities that bypassed the Mark-of-the-Web flag. The report cites these bypasses as another factor encouraging malicious attachment shifts.
Cisco Talos observed that the Qakbot BB campaign began showing metadata-wiping behavior on September 13, 2022. This mirrored the wiping already seen in the Obama campaign.
Talos found that some Gamaredon-linked samples identified on September 6 contained an embedded digital signature string referencing 'Microsoft Operations Puerto Rico1.' The string was likely garbage data inserted to confuse antivirus scanners.
Talos found that earlier September Qakbot BB campaign samples still contained Drive Serial Number information matching the AA campaign. This suggested the AA and BB campaigns were probably managed by the same group.
Cisco Talos said metadata correlation helped identify a new Gamaredon campaign targeting Ukrainian organizations beginning around August 8, 2022. Talos used LNK metadata to connect the activity to prior Gamaredon-linked samples.
Talos observed that starting in August 2022, the Qakbot Obama campaign wiped metadata from its LNK files. Despite the wiping, the Target field still pointed to JS, BAT, or CMD files used to launch the malicious DLL chain.
FortiGuard Labs analyzed a phishing campaign spreading a new QakBot variant through an attached HTML file that dropped a ZIP archive containing a malicious LNK. The shortcut used cmd.exe, curl, and regsvr32 to download and run a QakBot loader DLL, which then deployed the core module filelessly.
FortiGuard Labs published research describing active Q2 2022 phishing campaigns that evolved from Excel droppers to LNK files, ISO files, and HTML smuggling. The report tied the shift to Microsoft's tighter macro protections and attackers' preference for formats that better evade Mark-of-the-Web controls.
Cisco Talos said Microsoft re-enabled the macro-blocking changes by the end of July 2022. Talos observed a major spike in LNK-file usage around the period when these changes were in effect.
Cisco Talos said Microsoft removed the Office macro-blocking feature later in June 2022 after initially implementing it. Talos cited this sequence as part of the broader shift in attacker delivery methods during 2022.
By June 2022, FortiGuard Labs observed HTML smuggling files being sent directly as HTML attachments rather than only via download links. The campaigns continued delivering malware families including Emotet, Qbot, Icedid, and Bumblebee.
Talos analyzed multiple Qakbot AA campaign samples from June and July 2022 and found they were created on a machine with Drive Serial Number 0x2848e8a8. The same serial number also appeared in other malware-related samples, including one flagged as a RedLine variant.
Cisco Talos found that LNK metadata from a June 2022 Inquest report on the Glowsand threat actor linked to files associated with the Gamaredon APT. The correlation showed how LNK artifacts could connect apparently separate activity clusters.
Cisco Talos said Microsoft implemented macro-blocking changes for internet-downloaded Office documents around June 2022. Talos linked this change to increased attacker use of LNK files as initial access vectors.
FortiGuard Labs first observed phishing campaigns using HTML smuggling download links in May 2022. The technique reconstructed malicious files locally in the victim's browser.
FortiGuard Labs observed ISO droppers appearing in the middle of May 2022. These ISO files contained hidden malware DLLs and malicious LNK files used to launch payloads.
FortiGuard Labs reported that Qbot and IcedID began spreading through malicious Windows shortcut files in early May 2022. This marked a shift away from earlier Excel-based droppers.
FortiGuard Labs observed an Emotet attack technique using malicious LNK files for delivery. The report states this technique first appeared on April 23, 2022.
FortiGuard Labs observed Excel files as the only dropper type in early April 2022 in phishing-delivered malware campaigns targeting Windows users. These campaigns delivered malware including Emotet and Qbot.
FortiGuard Labs reported a spearphishing campaign using COVID-21 and Urgent Update lures against security-related entities within the Ukrainian government. The activity delivered ZIP archives with malicious LNK files, a Word exploit for CVE-2017-11882, AutoIT-based theft malware, and Saint_v3.
Cisco Talos and Fortinet both describe QakBot as an active malware operation first observed or analyzed around 2007.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
blog.talosintelligence.com
Open sourcefortinet.com
Open sourcefortinet.com
Open sourcefortinet.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.