HomeSecurityHackers bypass Windows MoTW files with LNK Stomping

Hackers bypass Windows MoTW files with LNK Stomping

A sophisticated attack technique called LNK Stomping has emerged as a critical threat to Windows security, exploiting a fundamental flaw in the way the operating system handles shortcut files to bypass security checks.

See also: Microsoft released Patch Tuesday April 2025

LNK Stomping
Hackers bypass Windows MoTW files with LNK Stomping

This vulnerability, designated as CVE-2024-38217 and patched on September 10, 2024, shows how attackers can manipulate Windows shortcuts (LNK files) to bypass the Mark of the Web (MoTW), potentially allowing malicious code to execute without triggering security warnings.

The attack technique exploits the Windows Explorer, causing the system to inadvertently strip MoTW metadata from malicious files. This bypass allows attackers to execute payloads while avoiding detection by Smart App Control (SAC) and SmartScreen, two critical Windows security components designed to protect users from untrusted downloads.

ASEC reports that LNK Stomping exploits the complex binary structure of Windows shortcut files, specifically targeting the LinkTarget IDList component. This section contains Shell Item IDs that specify the hierarchical location of target files within the Windows Shell namespace. Attackers manipulate this structure by creating non-standard path configurations that cause explorer.exe to perform normalization operations.

The attack follows a specific sequence when a user clicks on a maliciously crafted LNK file that contains non-standard path structures. Windows Explorer detects the non-standard configuration and attempts to normalize it. During this process, the system overwrites the original LNK file while inadvertently removing the NTFS Alternate Data Stream (ADS) called Zone.Identifier, which contains the MoTW metadata. This removal occurs before security checks are performed, allowing the malicious payload to execute without triggering defense mechanisms.

See also: WinRAR “Mark of the Web” vulnerability allows arbitrary code

Hackers bypass Windows MoTW files with LNK Stomping
Hackers bypass Windows MoTW files with LNK Stomping

Three main manipulation techniques have been identified: PathSegment attacks place entire file paths within a single IDList array element instead of properly segmented elements. Dot attacks add dots or spaces to target execution paths. Relative attacks use only file names without full path specifications, all creating structural inconsistencies that trigger the normalization vulnerability.

Security researchers at Elastic Security Labs have identified numerous LNK Stomping samples on VirusTotal, with the oldest submissions dating back six years, indicating that this technique has been exploited long before its official disclosure. The technique’s effectiveness is due to its ability to appear as legitimate system behavior. When LNK files are executed, they invoke trusted tools , allowing malicious activities to blend seamlessly with normal system operations.

CISA added CVE-2024-38217 to the list of Known Exploitable Vulnerabilities (KEV), confirming active exploitation by malicious actors. This approach has become increasingly popular following Microsoft's macro blocking policies implemented in 2022, forcing attackers to seek alternative initial access channels through file formats such as ISO, RAR, and LNK distributed via email attachments or compressed archives.

See also: 7-Zip MotW bypass used in zero-day attacks against Ukraine

Hackers bypass Windows MoTW files with LNK Stomping

Organizations face significant detection challenges because the attack exploits fundamental Windows file management mechanisms rather than external vulnerabilities. Traditional signature-based detection methods may fail to detect these attacks, as they exploit legitimate system processes and file structures. The persistence of this vulnerability for years before its discovery highlights the importance of format-level security research and behavioral analysis to identify previously unknown evasion techniques in known file types.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS