logo

New Windows zero-day exploited by 11 state hacking groups since 2017

ID: bf864b67-2931-5bab-b75f-337e87348cec

STIX ID: report--bf864b67-2931-5bab-b75f-337e87348cec

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-03-18

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Trend Micro's Zero Day Initiative disclosed ZDI-CAN-25373, a Windows UI-misrepresentation zero-day in .lnk shortcut handling that allows attackers to hide malicious command-line arguments and execute code; the flaw has been exploited in the wild since 2017 by multiple state-backed APTs and cybercrime groups (including Evil Corp, APT43/Kimsuky, Mustang Panda, and others) to deploy payloads such as Ursnif, Gh0st RAT, and Trickbot, while Microsoft has declined immediate servicing and has not yet issued a patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.