Nation-State Groups Abuse Microsoft Windows Shortcut Exploit
ID: fbdcf472-2671-516e-87d2-91c85045f879
STIX ID: report--fbdcf472-2671-516e-87d2-91c85045f879
Feed Name: Dark Reading
Date Published: 2025-03-19
Date Updated: 2026-04-21
Author: Alexander Culafi, Senior News Writer, Dark Reading
Trend Micro’s ZDI research reveals a Windows shortcut (.lnk) zero-day (ZDI-CAN-25373) actively used by at least 11 state-sponsored APT groups from North Korea, Iran, Russia, and China to execute hidden commands via crafted shortcut files for espionage and data theft across multiple sectors globally; Microsoft has classified the issue as low severity and has not issued an immediate patch, though Defender and Smart App Control provide some mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
