Skip to main content
← Back to Demos
LNK Abuse intermediate · 15 min

LNK invoking PowerShell download-and-execute chain

Microsoft's analysis of the ongoing clipper campaign shows the USB-spread shortcuts now rely on PowerShell-based payload stages, with the malware replacing cryptocurrency wallet addresses and communicating over Tor-based command-and-control. In this variant the LNK file launches powershell.exe with an encoded download cradle: a short script fetches a remote payload from the attacker's server and executes it in memory (MITRE T1059.001). Because the download happens at runtime, the shortcut itself contains no malware bytes for traditional scanners to find. Deep CDR removes the executable logic from the shortcut and reconstructs a sanitized version, breaking the download-and-execute chain before it starts. The demo runs a benign download-string against localhost, so it is safe for any test environment.

Attack Technique

LNK PowerShell download cradle

MITRE ATT&CK

T1059.001 ↗

Platforms

linuxwindows

File Types

.desktop

MetaDefender Capabilities

Deep CDR

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---