A sophisticated phishing campaign has been identified in which attackers distribute ZIP archives containing malicious Windows shortcut files (.lnk) disguised as legitimate documents such as payment records, certified documents, and passport scans. Cybersecurity researchers at Blackpoint Cyber discovered that these phishing emails are often tailored to target senior employees or managers, leveraging themes that mimic routine executive workflows like identity verification and payment approvals. When a recipient opens the ZIP file and clicks on a shortcut, a hidden PowerShell script is executed in the background without the user's knowledge. This script is designed to download a payload from a remote server, with the file masquerading as a PowerPoint presentation but actually being a malicious DLL. The attackers employ a technique known as 'living off the land,' using the legitimate Windows binary rundll32.exe to execute the downloaded DLL, thereby blending their activity with normal system operations and evading detection. The PowerShell dropper is further obfuscated and uses multiple 'quiet flags' to suppress any visible prompts or permission requests, making the attack stealthy and difficult for users to notice. The malicious activity is further camouflaged by leveraging signed Windows binaries, which are typically trusted by security controls. Blackpoint Cyber's Security Operations Center observed that the attackers deliberately mislabel the DLL to avoid suspicion. The campaign's success relies heavily on social engineering, exploiting the trust users place in document-themed content and the routine handling of ZIP archives in business environments. Security experts have recommended that organizations prohibit the use of LNK files within archives, enforce the Mark of the Web on downloaded files, and restrict the use of rundll32.exe to mitigate such threats. Additionally, enabling script block logging and transcription can help detect and investigate suspicious PowerShell activity. The campaign highlights the ongoing evolution of phishing tactics, with attackers increasingly using built-in system tools and trusted file formats to bypass traditional security measures. The use of identity-themed lures and executive targeting suggests a focus on high-value victims, potentially leading to significant organizational compromise if successful. The incident underscores the importance of user awareness training, robust email filtering, and endpoint monitoring to detect and prevent similar attacks. Organizations are urged to review their security policies regarding the handling of ZIP files and shortcut files, as well as to implement technical controls that can block or alert on suspicious script execution. The attack demonstrates how a single click on a seemingly innocuous file can result in the silent installation of malware, emphasizing the need for layered defenses. Security teams should remain vigilant for new variations of this technique, as attackers may adapt their methods to evade updated protections. The campaign serves as a reminder that even familiar file types and workflows can be weaponized by threat actors to gain initial access to corporate networks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Security reporting described a malware distribution technique in which malicious ZIP archives contain weaponized Windows shortcut (.LNK) files that trigger malware delivery when opened. The references do not provide a more specific discovery date, so the event is dated from the publication date of the reports.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.