logo

Nation-State Groups Abuse Microsoft Windows Shortcut Exploit

ID: fbdcf472-2671-516e-87d2-91c85045f879

STIX ID: report--fbdcf472-2671-516e-87d2-91c85045f879

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-03-19

Date Updated: 2026-04-21

Author: Alexander Culafi, Senior News Writer, Dark Reading

...
...

Trend Micro’s ZDI research reveals a Windows shortcut (.lnk) zero-day (ZDI-CAN-25373) actively used by at least 11 state-sponsored APT groups from North Korea, Iran, Russia, and China to execute hidden commands via crafted shortcut files for espionage and data theft across multiple sectors globally; Microsoft has classified the issue as low severity and has not issued an immediate patch, though Defender and Smart App Control provide some mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.