• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Malicious LNK Persistence Dropped via WScript.Shell in Startup Folder

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 21 days ago•0•0•1

    Detects the creation of a .lnk shortcut file within the Windows Startup folder, which is a common persistence mechanism. The detection logic also flags the usage of WScript.Shell and CreateShortcut methods, which are frequently abused by scripts (e.g., VBScript or PowerShell) to programmatically establish this persistence.

    Sigma

    Tags

    T1547.001 - Registry Run Keys / Startup FolderT1059.005 - Visual BasicTA0003 - PersistenceTA0002 - ExecutionFile CreationProcess CreationScript ExecutionWindowsWindows Sysmonattack.persistenceattack.t1547.001attack.t1059.005

    Found in

    • ClickFix Campaign Targets News Outlet with StealCLast updated 21 days ago
    • ClickFix Campaign Targets News Outlet with StealCLast updated 21 days ago
    • ClickFix Campaign Targets News Outlet with StealCLast updated 21 days ago
    • ClickFix Campaign Targets News Outlet with StealCLast updated 21 days ago
    • ClickFix Campaign Targets News Outlet with StealCLast updated 21 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?