Threat actors are increasingly using malicious Windows shortcut (.lnk) files to execute payloads through trusted Windows components such as Explorer and other living-off-the-land binaries (LOLBins), shifting away from macro-based initial access techniques that have become less reliable due to Microsoft hardening. The activity highlighted by SentinelOne shows attackers embedding commands and execution chains inside shortcut files so that user interaction with what appears to be a benign file can trigger malware delivery while blending into normal operating system behavior.
The technique allows adversaries to evade defenses that focus on Office macros and to reduce the need for custom droppers by abusing native binaries already present on Windows systems. For defenders, the reporting underscores the need to inspect .lnk files, monitor suspicious child processes spawned by explorer.exe, and hunt for unusual LOLBin execution patterns tied to shortcut launches, as these methods can support phishing, malware staging, and broader post-compromise activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
SentinelOne published research describing threat actors shifting from macro-based delivery to abusing Windows shortcuts and LOLBins such as Explorer for malicious execution. The reference does not provide a specific earlier event date, so the publication date is used as the timeline marker.
Proofpoint reported that from October 2021 through June 2022, email-borne malware campaigns using macro-enabled attachments fell by about 66% while use of container files such as ISO and RAR and Windows Shortcut (LNK) files rose sharply. The company highlighted a 1,675% increase in campaigns containing LNK files and more than 150% growth in ISO use as threat actors adapted to macro blocking in Office.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
sentinelone.com
Open sourcedocs.microsoft.com
Open sourcedocs.microsoft.com
Open sourcedocs.microsoft.com
Open sourceattack.mitre.org
Open sourcecert.gov.ua
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.