logo

Windows zero-day actively exploited to spy on European diplomats

ID: 734b996c-2176-5c6a-a81f-b854dd79a34d

STIX ID: report--734b996c-2176-5c6a-a81f-b854dd79a34d

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-10-31

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

Arctic Wolf Labs and other researchers report a China-linked APT (UNC6384/Mustang Panda) conducting a spearphishing-driven cyber‑espionage campaign that leverages a Windows LNK zero‑day (CVE-2025-9491) to deploy the PlugX RAT against diplomatic targets across Europe; exploitation is active, broadening in scope, and currently unpatched, with multiple state-backed groups and cybercrime actors observed abusing the flaw.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.