Using a .lnk filepath contains a series of errors that stop the ransomware even before the encryption process.
Researchers noted that creating a malicious '.lnk' file format can protect your systems from executing at least some samples of the Lockergoga ransomware .
LockerGoga that, the ransomware hit aluminum giant Norsk Hydro and two other American chemical companies, contains a bug in its code that could allow victims to "vaccinate" their systems and stop the ransomware even before it starts encrypting files.
Security researchers from Alert Logic revealed the ransomware's coding flaw.

Researchers report that the ransomware, when it hit the host system, performed an initial identification scan to collect lists of files before starting the encryption process.
- File lists include a .lnk file extension, which is a shortcut used in Windows to link files.
- This .lnk file uses the built-in shell32/linkinfo DLLs to resolve the '.lnk' path.
- However, the .lnk filepath contains a series of errors, which stop the ransomware even before the encryption process.
Researchers have discovered two possible ways to prevent ransomware from being delivered via the .lnk file:
- The .lnk file was created to contain an invalid network path.
- The file '.lnk' has no associated RPC endpoint.
It is worth noting that researchers emphasized that creating a malicious .lnk file can protect your systems from executing at least some samples of the Lockergoga ransomware.
