A while back, Jesse Kornblum published a paper titled, " that referred to a phishing campaign (using LNK files) by APT29/"Cozy Bear". In the article, the authors compare activity from a similar campaign from 2016, using LNK files from the previous campaign (see figures 5 & 6).
One such example of where the content falls short is a
What we see in figure 1 also shows that the author(s) had access to the LNK files themselves, and could have done so much more with them.
Hashes for the LNK files are also listed in the IoCs table at the end of the article, and I was able to find one of the file available for download via another site online, and was able to extract the metadata illustrated in figure 2.
| , which isn't something we see in every LNK file, and can provide insight into how the shortcut file was "constructed". Different methodologies and tools for creating LNK files |
| Figure 3: LNK header+ |
The original article was published on 19 Dec 2024, which provides some idea as to the timeframe of when the LNK file would have been deployed in a campaign, collected, and analyzed. Using the information illustrated in figure 3, we get some additional insight as to the timeframe specifically associated with the LNK file, particularly those time stamps within the shell items.
In addition to the volume serial number (i.e., "280C-1822"), the time stamps and MFT reference numbers extracted from the shell items provides additional indicators that can be used to align with LNK files from other campaigns.
Another such example is , but rather than being as verbose as the previous example from the Cyble article, these LNK files simply contained a SID:
S-1-5-21-3861309104-3271506253-2070734288-1001
Okay, but so what? Why does any of this matter?
Well, these indicators, when combined and added to other indicators, tell us a good bit about the operational processes of the threat actor, as well as the, essentially removing those indicators. However, I'd be careful about any assumptions made regarding a threat group's situational awareness or operational security based on metadata within LNK files; the simple fact is that this information is largely left unused by many firms, so why bother with the extra steps or work to remove the indicators?
SOCIAL SHARE CARD GENERATOR