logo

Microsoft isn't fixing 8-year-old shortcut exploit abused for spying

ID: 9261a22e-58b4-5d65-a339-7d4da39cc0ef

STIX ID: report--9261a22e-58b4-5d65-a339-7d4da39cc0ef

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2025-03-18

Date Updated: 2026-04-26

Author: Iain Thomson

...
...

Trend Micro's Zero Day Initiative disclosed a Windows shortcut (.LNK) exploitation technique—used since around 2017—where attackers hide malicious command-line instructions by inserting megabytes of whitespace in shortcut arguments; the firm found nearly 1,000 tampered .LNK files and attributes roughly 70% of samples to state-sponsored actors (46% North Korea). Trend reported the issue to Microsoft as a zero-day, but Microsoft has treated it as a UI issue and has not issued an immediate security patch, leaving the vector available for espionage and malware delivery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.