doc2lnk is a security-research project I built for a networking-security (NETSEC) course to study how Windows .lnk shortcut files can be abused to disguise executable behavior as an ordinary document. It’s a hands-on demonstration of a well-documented social-engineering technique, the kind defenders need to recognize, since .lnk masquerading shows up regularly in real phishing campaigns.
The technique it demonstrates
A .lnk file looks like a harmless shortcut and can be given a document’s name and icon, but it actually points at another program and can pass arguments to it. doc2lnk shows the two halves of the trick that make this convincing:
- The disguise, the shortcut takes the document’s icon and name, so in a file listing it reads as the document rather than as a shortcut.
- The embedded payload, the original document’s bytes are appended to the end of the
.lnkafter a delimiter, and a companion PowerShell routine can locate that delimiter, carve the document back out to a temp file, and open it. The point is that the real document can travel inside the shortcut and still be shown, which is exactly what makes a malicious shortcut look legitimate to the person who clicks it.
Why it’s interesting defensively
The reason this matters for a security course is detection and mitigation: understanding that a .lnk can carry an icon spoof, a hidden command line, and trailing data gives you concrete things to look for, shortcuts whose target isn’t the document they appear to be, oversized .lnk files, and shortcuts that invoke a shell interpreter. Building the technique end to end made those indicators obvious in a way reading about them didn’t.
The project is a Python package (python3 -m doc2lnk ...) built on pylnk3, with the commit history tracked as NETSEC tickets.
Source
The code is on GitHub: Skimak/doc2lnk
>> Home