logo

ZDI-CAN-25373: Windows Shortcut Exploit Abused as Zero-Day in Widespread APT Campaigns

ID: 91ed6416-a3d0-56ab-a70f-d4f29bdb15fd

STIX ID: report--91ed6416-a3d0-56ab-a70f-d4f29bdb15fd

Feed Name: TrendAI Security Blog

Threat Score
90/100

Date Published: 2026-01-01

Date Updated: 2026-08-12

...
...

Trend ZDI identified widespread active exploitation of a Windows Shortcut UI-misrepresentation zero-day (ZDI-CAN-25373) that conceals command-line arguments within .lnk files to execute malicious payloads; nearly 1,000 samples tied to multiple state-sponsored APTs (notably North Korean groups) have been observed since 2017, targeting government, financial, telecom, military, energy and other sectors worldwide, and the report provides technical details, detection rules (YARA), hunting queries, IoCs, and Trend mitigations while noting Microsoft declined to patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.