216.73.217.98

CVE-2025-0411: Ukrainian Organizations Targeted in Zero-Day Campaign and Homoglyph Attacks

· Published 04/02/2025 16:46 · Modified 05/02/2025 16:47

Export JSON

Essential information

Published
04/02/2025 16:46
Modified
05/02/2025 16:47
Tags
2025-02-04 7-zip CVE-2025-0411 cyberespionage homoglyph attacks mark-of-the-web bypass smokeloader spear-phishing zero-day
Related entities
1 intrusion sets (apt), 6 techniques (mitre), 1 malware, 4 others

Description

A vulnerability in () was exploited by Russian cybercrime groups to target Ukrainian organizations. The vulnerability allows bypassing Windows Mark-of-the-Web protections through double archiving, enabling execution of malicious content. The campaign involved emails with to trick users into executing malicious files. The exploit was likely part of a effort in the ongoing Russo-Ukraine conflict. Affected organizations include government entities and businesses. Recommendations include updating , implementing email security measures, and training employees on phishing and .

External references