Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

MITRE ATT&CK T1027.012: LNK Icon Smuggling (Enterprise Tactic TA0005 - Defense Evasion)

MITRE ATT&CK T1027.012 (LNK Icon Smuggling) is an Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may…

What MITRE ATT&CK T1027.012: LNK Icon Smuggling (Enterprise Tactic TA0005 - Defense Evasion) requires

MITRE ATT&CK T1027.012 (LNK Icon Smuggling) is an Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may smuggle commands to download malicious payloads past content filters by hiding them within otherwise seemingly benign windows shortcut files. Windows shortcut files (.LNK) include many metadata fields, including an icon location field (also known as the IconEnvironmentDataBlock) designed to specify the path to an icon file that is to be displayed for the LNK file within a host directory. Adversaries may abuse this LNK metadata to download malicious payloads. Affected platforms: Windows. MITRE-documented mitigations include M1049 Antivirus/Antimalware, M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-03, CM-02, CM-06, CM-07, SI-02, SI-03, SI-04, SI-07.

Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:

Primary source: https://attack.mitre.org/techniques/T1027/012/

SHA-256 integrity: 1d13c5bcd856b370c64331c5b181ea864e7dde69665cc6f4e64cac8703af311a

Primary Citations — 7 traced to source

  • MITRE ATT&CK Technique T1027.012: LNK Icon Smuggling (https://attack.mitre.org/techniques/T1027/012/)
  • MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.