LNK Icon Smuggling

T1027.012

Sub-technique of T1027 Obfuscated Files or Information.View on attack.mitre.org

About this technique

Adversaries may smuggle commands to download malicious payloads past content filters by hiding them within otherwise seemingly benign windows shortcut files. Windows shortcut files (.LNK) include many metadata fields, including an icon location field (also known as the `IconEnvironmentDataBlock`) designed to specify the path to an icon file that is to be displayed for the LNK file within a host directory.

Adversaries may abuse this LNK metadata to download malicious payloads. For example, adversaries have been observed using LNK files as phishing payloads to deliver malware. Once invoked (e.g., Malicious File), payloads referenced via external URLs within the LNK icon location field may be downloaded. These files may also then be invoked by Command and Scripting Interpreter/System Binary Proxy Execution arguments within the target path field of the LNK.

LNK Icon Smuggling may also be utilized post compromise, such as malicious scripts executing an LNK on an infected host to download additional malicious payloads.

Detection rules0

Rules on DetectionCode tagged with T1027.012.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups3

Software1

Campaigns0

None recorded.

Procedure examples4

Groups3

Used byProcedure example
GroupGamaredon Group

Gamaredon Group has used LNK files to hide malicious scripts for execution.

GroupKimsuky

Kimsuky has used the LNK icon location to execute malicious scripts. Kimsuky has also padded the LNK target field properties with extra spaces to obscure the script.

GroupMustang Panda

Mustang Panda has utilized LNK files to hide malicious scripts for execution. Mustang Panda has also leveraged LNK files that were programmed to display a PDF icon to entice the victim to click on the file to execute an office.exe binary.

Software1

Used byProcedure example
MalwareTONESHELL

TONESHELL has been initiated using LNK files that were programmed to display a PDF icon to entice the victim to click on the file to execute an office.exe binary.

References2

  1. Booby Trap Shortcut 2017 Open source
    Weyne, F. (2017, April). Booby trap a shortcut with a backdoor. Retrieved October 3, 2023.
  2. Unprotect Shortcut Open source
    Unprotect Project. (2019, March 18). Shortcut Hiding. Retrieved October 3, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.