What MITRE ATT&CK T1027.012: LNK Icon Smuggling (Enterprise Tactic TA0005 - Defense Evasion) requires
MITRE ATT&CK T1027.012 (LNK Icon Smuggling) is an Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may smuggle commands to download malicious payloads past content filters by hiding them within otherwise seemingly benign windows shortcut files. Windows shortcut files (.LNK) include many metadata fields, including an icon location field (also known as the IconEnvironmentDataBlock) designed to specify the path to an icon file that is to be displayed for the LNK file within a host directory. Adversaries may abuse this LNK metadata to download malicious payloads. Affected platforms: Windows. MITRE-documented mitigations include M1049 Antivirus/Antimalware, M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-03, CM-02, CM-06, CM-07, SI-02, SI-03, SI-04, SI-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1027/012/
SHA-256 integrity: 1d13c5bcd856b370c64331c5b181ea864e7dde69665cc6f4e64cac8703af311a
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1027.012: LNK Icon Smuggling (https://attack.mitre.org/techniques/T1027/012/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1027-012-lnk-icon-smuggling.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1027-012-lnk-icon-smuggling.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1027-012-lnk-icon-smuggling
- Back to registry: Browse all 10,085 compliance nodes