Shortcut file whose target string hides a command payload
Microsoft published an analysis of a clipper malware campaign that spreads through infected USB drives using LNK file exploits, swapping cryptocurrency wallet addresses in the clipboard to redirect funds, with Tor-based C2. Weaponized shortcuts are the delivery trick: the .lnk target field points not at a program but at cmd.exe with a hidden command, so a double-click silently executes the payload (MITRE T1204.001). Because the malicious logic lives in the shortcut's metadata, it can evade signature checks that ignore LNK structure. Deep CDR parses the shortcut, strips the embedded command, and rebuilds a clean shortcut that opens the intended application only. The demo uses a benign cmd /c calc payload, safe to run on any Windows machine.
Attack Technique
LNK shortcut with cmd payload
MITRE ATT&CK
T1204.001 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗