Vulnerability Nature & Exploitation:
Threat actors utilized specially crafted internet shortcut files (.url) distributed inside zip archives. When launched, the shortcut forced the invocation of the deprecated Internet Explorer (MSHTML) engine in the background—even if the default browser was Chrome or Edge—bypassing security controls and dropping malicious payloads.
Remediation Steps:
- Windows Cumulative Update: Install the Microsoft July 2024 security updates immediately.
- File Hygiene: Never open untrusted .url or shortcut files received via email or messaging platforms.
