LNK invoking PowerShell download-and-execute chain
Microsoft's analysis of the ongoing clipper campaign shows the USB-spread shortcuts now rely on PowerShell-based payload stages, with the malware replacing cryptocurrency wallet addresses and communicating over Tor-based command-and-control. In this variant the LNK file launches powershell.exe with an encoded download cradle: a short script fetches a remote payload from the attacker's server and executes it in memory (MITRE T1059.001). Because the download happens at runtime, the shortcut itself contains no malware bytes for traditional scanners to find. Deep CDR removes the executable logic from the shortcut and reconstructs a sanitized version, breaking the download-and-execute chain before it starts. The demo runs a benign download-string against localhost, so it is safe for any test environment.
Attack Technique
LNK PowerShell download cradle
MITRE ATT&CK
T1059.001 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗