Skip to main content
← Back to Demos
LNK Abuse beginner · 15 min

Shortcut file whose target string hides a command payload

Microsoft published an analysis of a clipper malware campaign that spreads through infected USB drives using LNK file exploits, swapping cryptocurrency wallet addresses in the clipboard to redirect funds, with Tor-based C2. Weaponized shortcuts are the delivery trick: the .lnk target field points not at a program but at cmd.exe with a hidden command, so a double-click silently executes the payload (MITRE T1204.001). Because the malicious logic lives in the shortcut's metadata, it can evade signature checks that ignore LNK structure. Deep CDR parses the shortcut, strips the embedded command, and rebuilds a clean shortcut that opens the intended application only. The demo uses a benign cmd /c calc payload, safe to run on any Windows machine.

Attack Technique

LNK shortcut with cmd payload

MITRE ATT&CK

T1204.001 ↗

Platforms

linuxwindows

File Types

.desktop

MetaDefender Capabilities

Deep CDR

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---