New Windows zero-day exploited by 11 state hacking groups since 2017
ID: bf864b67-2931-5bab-b75f-337e87348cec
STIX ID: report--bf864b67-2931-5bab-b75f-337e87348cec
Feed Name: Bleeping Computer
Trend Micro's Zero Day Initiative disclosed ZDI-CAN-25373, a Windows UI-misrepresentation zero-day in .lnk shortcut handling that allows attackers to hide malicious command-line arguments and execute code; the flaw has been exploited in the wild since 2017 by multiple state-backed APTs and cybercrime groups (including Evil Corp, APT43/Kimsuky, Mustang Panda, and others) to deploy payloads such as Ursnif, Gh0st RAT, and Trickbot, while Microsoft has declined immediate servicing and has not yet issued a patch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
