216.73.216.6

Windows Shortcut Exploit Abused as Zero-Day in Widespread APT Campaigns

· Published 18/03/2025 20:59 · Modified 19/03/2025 09:51

Export JSON

Essential information

Published
18/03/2025 20:59
Modified
19/03/2025 09:51
Tags
2025-03-18 apt command execution data theft espionage lnk raspberry robin shortcut vulnerability windows zero-day
Related entities
200 observables, 6 techniques (mitre), 1 malware, 38 others

Description

A . file , ZDI-CAN-25373, has been extensively exploited by state-sponsored and cybercriminal groups. The allows hidden through crafted files, exposing organizations to and cyber risks. Nearly 1,000 malicious . files abusing this have been identified, with groups from North Korea, Iran, Russia, and China involved in the attacks. Targeted sectors include government, finance, telecommunications, military, and energy across North America, Europe, Asia, South America, and Australia. The exploitation leverages hidden command line arguments within . files, complicating detection. Organizations are urged to implement security measures and maintain vigilance against suspicious . files.

External references