Rapid7

module

Right-Click Execution - Windows LNK File Special UNC Path NTLM Leak

Disclosed
May 6, 2025
Created
Oct 1, 2025

Description

This module creates a malicious Windows shortcut (LNK) file that
specifies a special UNC path in EnvironmentVariableDataBlock of Shell Link (.LNK)
that can trigger an authentication attempt to a remote server. This can be used
to harvest NTLM authentication credentials.

When a victim right-click the generated LNK file, it will attempt to connect to the
the specified UNC path, resulting in an SMB connection that can be captured
to harvest credentials.

Author

Nafiez

Platform

Windows

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use auxiliary/fileformat/environment_variable_datablock_leak
msf auxiliary(environment_variable_datablock_leak) > show actions
...actions...
msf auxiliary(environment_variable_datablock_leak) > set ACTION < action-name >
msf auxiliary(environment_variable_datablock_leak) > show options
...show and set options...
msf auxiliary(environment_variable_datablock_leak) > run

Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.