logo

Nation-state actors and cybercrime gangs abuse malicious .lnk files for espionage and data theft

ID: fbf9d5d1-9d94-5f82-b070-f871ba30af3e

STIX ID: report--fbf9d5d1-9d94-5f82-b070-f871ba30af3e

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2025-03-18

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Trend Micro’s Zero Day Initiative (ZDI) reports that at least 11 state-sponsored APTs and cybercrime groups are actively abusing a Windows Shell Link (.lnk) zero-day (ZDI-CAN-25373) to hide and execute malicious commands, with roughly 1,000 malicious .lnk samples discovered. The technique abuses UI misrepresentation (CWE-451) by padding .lnk files to hide command-line arguments, enabling stealthy delivery of various malware payloads across government, financial, telecom, military and energy sectors worldwide; Microsoft was notified but declined to issue a patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.