logo

8-Year Old Windows Shortcut Zero-Day Exploited by 11 State-Sponsored Hacker Groups

ID: 0b08991c-a798-550f-8086-23ee6093b0d2

STIX ID: report--0b08991c-a798-550f-8086-23ee6093b0d2

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2025-03-18

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Researchers (Trend Micro) report that a long-exploited Windows shortcut vulnerability (ZDI-CAN-25373) lets attackers hide and execute malicious commands by padding the COMMAND_LINE_ARGUMENTS in .lnk files with whitespace. The technique has been used since 2017 by at least 11 state-sponsored groups — notably North Korean actors — in espionage and data-theft campaigns, with nearly 1,000 malicious .lnk files observed across government, finance, telecommunications and other sectors; Microsoft classifies the issue as low severity and will not patch, so defenders are advised to hunt for suspicious .lnk files and apply mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.