{"id":8084,"date":"2025-10-31T10:03:28","date_gmt":"2025-10-31T10:03:28","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/31\/hackers-weaponizing-windows-lnk-file-ui-misrepresentation-remote-code-execution-vulnerability\/"},"modified":"2025-10-31T10:03:28","modified_gmt":"2025-10-31T10:03:28","slug":"hackers-weaponizing-windows-lnk-file-ui-misrepresentation-remote-code-execution-vulnerability","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/31\/hackers-weaponizing-windows-lnk-file-ui-misrepresentation-remote-code-execution-vulnerability\/","title":{"rendered":"Hackers Weaponizing Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability"},"content":{"rendered":"<p>    Hackers Weaponizing Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Chinese-affiliated threat actor UNC6384 has been actively leveraging a critical Windows shortcut vulnerability to target European diplomatic entities across Hungary, Belgium, Serbia, Italy, and the Netherlands.<\/p>\n<p>Arctic Wolf researchers identified this sophisticated cyber espionage campaign operating throughout September and October 2025, representing a significant evolution in the group\u2019s operational capabilities and geographic reach.<\/p>\n<p>The attack begins with carefully crafted spearphishing emails containing URLs that deliver malicious <a href=\"https:\/\/cybersecuritynews.com\/hackers-deliver-weaponized-lnk-files\/\" target=\"_blank\" rel=\"noreferrer noopener\">LNK files<\/a> disguised as legitimate diplomatic conference agendas.<\/p>\n<p>These files reference authentic European Commission meetings, NATO defense procurement workshops, and multilateral coordination events.<\/p>\n<p>When users click these seemingly innocent shortcuts, a critical flaw in Windows shortcut handling enables silent command execution that most detection systems fail to catch.<\/p>\n<p>UNC6384 rapidly adopted the ZDI-CAN-25373 vulnerability within just six months of its March 2025 public disclosure, demonstrating exceptional operational agility and vulnerability tracking capabilities.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEihzM916W9n2_oUkD6t5CvR72c0OkZQ-Hsst3-yxCinsXvuFpf_Ghpbj73icnS6oh2_AdF57ib6hMdHiFJ8MbmKt2mfABvsHEIrDXfyRiN2PPCqa43uq3Kjw2Nj4Bqh5djL8VydMonrKsdI6MHao7MYbF2JL8BTZpuj3hjlK9QR_hPWfaOm1zQzuhSbmNA\/s16000\/Execution%2520chain%2520%28Source%2520-%2520Arctic%2520Wolf%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Execution chain (Source \u2013 Arctic Wolf)<\/figcaption><\/figure>\n<\/div>\n<p>Arctic Wolf analysts <a href=\"https:\/\/arcticwolf.com\/resources\/blog\/unc6384-weaponizes-zdi-can-25373-vulnerability-to-deploy-plugx\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">detected<\/a> the malware after the second paragraph of research, noting the sophisticated infection mechanism that builds a complex multi-stage attack chain designed to evade traditional security defenses.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-technical-infection-mechanism-and-payload-delivery\"><strong>Technical Infection Mechanism and Payload Delivery<\/strong><\/h2>\n<p>The exploitation mechanism cleverly abuses whitespace padding within the LNK file\u2019s COMMAND_LINE_ARGUMENTS structure to hide malicious commands from user visibility.<\/p>\n<p>Upon execution, the compromised shortcut silently invokes PowerShell to extract and decompress a tar archive containing three critical components: a legitimate, digitally signed Canon printer utility, a malicious DLL loader, and an encrypted PlugX remote access trojan payload.<\/p>\n<p>The attack chain employs <a href=\"https:\/\/cybersecuritynews.com\/mustang-panda-using-new-dll-side-loading\/\" target=\"_blank\" rel=\"noreferrer noopener\">DLL side-loading<\/a>, exploiting standard Windows library search order processes. When the Canon executable launches, it instinctively searches for supporting libraries in its local directory before checking system folders.<\/p>\n<p>The malicious DLL positioned there transparently loads, then decrypts the PlugX payload using a hardcoded RC4 key and injects it directly into the legitimate process\u2019s memory space, creating a nearly undetectable persistent backdoor.<\/p>\n<p>The PlugX malware establishes encrypted HTTPS command and control connections using randomized parameters across multiple redundant domains including racineupci[.]org and dorareco[.]net.<\/p>\n<p>The malware creates hidden persistence directories with spoofed names like \u201cSamsungDriver\u201d and modifies Windows registry Run keys, ensuring continued access across system restarts.<\/p>\n<p>This campaign demonstrates nation-state level sophistication, combining zero-day exploitation knowledge with meticulous <a href=\"https:\/\/cybersecuritynews.com\/social-engineering-tactics\/\" target=\"_blank\" rel=\"noreferrer noopener\">social engineering<\/a> targeting specific diplomatic personnel and events, representing a substantial intelligence collection threat to European government operations.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hackers-weaponizing-windows-lnk-file-ui\/\">Hackers Weaponizing Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hackers-weaponizing-windows-lnk-file-ui\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Weaponizing Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability Chinese-affiliated threat actor UNC6384 has been actively leveraging a critical Windows shortcut vulnerability to target European diplomatic entities across Hungary, Belgium, Serbia, Italy, and the Netherlands. Arctic Wolf researchers identified this sophisticated cyber espionage campaign operating throughout September and October 2025, representing a significant [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-8084","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8084"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8084"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8084\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8084"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8084"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8084"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}