Elastic Security Labs Uncovers Techniques to Bypass Windows SmartScreen

06 Aug 2024

Elastic Security Labs has unveiled a range of techniques that malicious actors might employ to execute harmful applications while evading Windows’ security alerts. Among these methods is one that has been in circulation for six years, drawing attention to the vulnerabilities within the operating system’s protective measures.

Bypassing Windows Protections

The research, led by Joe Desimone, the tech lead at Elastic, delves into strategies to circumvent Windows SmartScreen and Smart App Control (SAC). These built-in defenses are designed to protect users from potentially harmful software downloaded from the internet, particularly in Windows 8 and 11. One notable technique identified by Desimone is termed “LNK Stomping.” This exploits a flaw in how Windows handles shortcut files (.LNK), effectively nullifying the Mark of the Web (MotW)—a digital label indicating that a file may be dangerous if executed.

SmartScreen only scans files that carry the MotW tag, while SAC blocks certain file types marked in this way. Thus, any method that can bypass MotW becomes a significant advantage for those looking to deploy malware.

While this is not the first method to bypass MotW, its longevity and ease of exploitation warrant attention from cybersecurity defenders. Desimone emphasized that understanding this technique is crucial, even though Elastic has yet to receive concrete mitigation promises from Microsoft, which indicated that a fix might be forthcoming in future updates.

The “trivial” nature of this technique involves creating LNK files with unconventional target paths or internal structures. This prompts Windows Explorer to rectify these minor discrepancies before launching the malicious application. In doing so, the MotW is stripped away, allowing SmartScreen and SAC to overlook the potential threat.

Desimone noted that a simple way to trigger this vulnerability is by appending a period or a space in the target executable path, such as target.exe. or .target.exe. Windows Explorer recognizes the error, searches for the actual executable, corrects the path, and subsequently removes the MotW tag.

“We identified multiple samples in VirusTotal that exhibit the bug, demonstrating existing in-the-wild usage,” Desimone remarked. “The oldest sample identified was submitted over six years ago. We have also disclosed the bug’s details to the Microsoft Security Response Center (MSRC) and are releasing this information, along with detection logic and countermeasures, to aid defenders until a patch is available.”

In the interim, security professionals are encouraged to refine their detection strategies to address the vulnerabilities highlighted by SmartScreen and SAC.

Other Bypass Techniques

SmartScreen and SAC rely on reputation-based protections, and historically, one of the more challenging methods to bypass these systems has involved signing a malicious application with a code-signing certificate. Although acquiring such certificates should be difficult, given that certificate authorities are expected to issue them only to legitimate businesses, this remains a feasible tactic.

Desimone also pointed out several additional methods for circumventing reputation-based protections. One such technique, dubbed Reputation Hijacking, entails identifying a legitimate program with a strong reputation and manipulating it for malicious purposes. Script hosts are particularly vulnerable to this type of attack, but any application that can be controlled without common line parameters is also at risk. The presence of a foreign function interface (FFI) capability enhances the potential for loading harmful code into memory, making interpreters like Lua, Node.js, and AutoHotkey prime targets for exploitation.

Another method, Reputation Seeding, appears to be particularly effective. This involves creating a benign application and distributing it widely to build a positive reputation before injecting malicious code into it at a later stage. The initial benign behavior helps it evade detection by reputation-based systems until it’s too late.

As these techniques continue to evolve, cybersecurity professionals must stay vigilant and proactive in adapting their defenses. The research from Elastic Security Labs serves as a crucial reminder of the ever-changing landscape of cyber threats and the importance of continuous innovation in security measures.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7380466
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1701802
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
730738
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
491619
downloads

News and reviews for Desktop Windows

Microsoft Issues Emergency Windows 11 Shutdown Fix

Microsoft releases an out-of-band update for Windows 11 to resolve shutdown and remote login issues caused by a security update.

Read more

Torchlight Infinite's Vorax Update Hits Player Peak on Steam

Torchlight Infinite's Vorax season update sets a new player record on Steam, introducing innovative features and timing its release for maximum impact.

Read more

Explore Stunning Videogame Art from Dishonored to Avowed

PC Gamer writers discuss iconic art in games like Dishonored, Destiny, Elden Ring, and Avowed. Delve into rich visuals and memorable designs.

Read more

Heartopia Faces Mixed Reviews on Steam Launch

Heartopia launched on Steam in January 2026, drawing mixed reviews. Key issues include PC controls and monetization concerns.

Read more

Arc Raiders Sells 12.4M Copies, Spurs Major 2026 Update Plans

Arc Raiders' success prompts Embark to plan ambitious 2026 updates, focusing on new maps, trading systems, and potential social features.

Read more

Hytale Adds Dinosaurs in Major Update

Hytale adds dinosaurs and fixes bugs days after release, boosting early access with new features.

Read more

Claim Free Games on Epic and Steam Now

Epic Games Store and Steam offer free games until mid-January. Claim Styx titles and Initial Drift Online to expand your library.

Read more

Thief 2 Fan Mission 'Selection Day' Elevates Puzzle Gameplay

The fan mission Selection Day for Thief 2 offers a unique, sound-focused puzzle experience set in a post-Metal Age City.

Read more

Nvidia GPUs Hit by FPS Drops After January Windows Update

Nvidia GPUs experience FPS drops in gaming due to January 2026 Windows Update KB5074109. Users apply fixes to mitigate the impact.

Read more

Epic Games Offers Free Styx Games Ahead of New Release

Epic Games Store offers free Styx titles until 2024-01-22. New entry, Blades of Greed, launches 2024-02-19.

Read more