CVE-2025-0411: Ukrainian Organizations Targeted in Zero-Day Campaign and Homoglyph Attacks
Essential information
- Published
- 04/02/2025 16:46
- Modified
- 05/02/2025 16:47
- Tags
- 2025-02-04 7-zip CVE-2025-0411 cyberespionage homoglyph attacks mark-of-the-web bypass smokeloader spear-phishing zero-day
- Related entities
- 1 intrusion sets (apt), 6 techniques (mitre), 1 malware, 4 others
Description
A zero-day vulnerability in 7-Zip (CVE-2025-0411) was exploited by Russian cybercrime groups to target Ukrainian organizations. The vulnerability allows bypassing Windows Mark-of-the-Web protections through double archiving, enabling execution of malicious content. The campaign involved spear-phishing emails with homoglyph attacks to trick users into executing malicious files. The exploit was likely part of a cyberespionage effort in the ongoing Russo-Ukraine conflict. Affected organizations include government entities and businesses. Recommendations include updating 7-Zip, implementing email security measures, and training employees on phishing and homoglyph attacks.