Windows zero-day actively exploited to spy on European diplomats
ID: 734b996c-2176-5c6a-a81f-b854dd79a34d
STIX ID: report--734b996c-2176-5c6a-a81f-b854dd79a34d
Feed Name: Bleeping Computer
Threat Score
Arctic Wolf Labs and other researchers report a China-linked APT (UNC6384/Mustang Panda) conducting a spearphishing-driven cyber‑espionage campaign that leverages a Windows LNK zero‑day (CVE-2025-9491) to deploy the PlugX RAT against diplomatic targets across Europe; exploitation is active, broadening in scope, and currently unpatched, with multiple state-backed groups and cybercrime actors observed abusing the flaw.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
