HomeSecurityHackers exploit RCE vulnerability via Windows LNK files

Hackers exploit RCE vulnerability via Windows LNK files

The China-linked hacker group UNC6384 has been actively exploiting a critical vulnerability in Windows, targeting diplomatic entities in Europe, including Hungary, Belgium, Serbia, Italy, and the Netherlands. Arctic Wolf researchers identified this sophisticated cyberespionage campaign operating throughout September and October 2025, representing a significant evolution in the group’s operational capabilities and geographic reach.

See also: RediShell RCE vulnerability: Over 8,500 vulnerable Redis instances

Windows RCE

The attack begins with carefully crafted spearphishing emails containing URLs that deliver malicious LNK files disguised as legitimate diplomatic conference agendas. These files refer to authentic European Commission meetings, NATO defense procurement workshops, and multilateral coordination events.

When users click on these seemingly innocent shortcuts, a critical vulnerability in Windows shortcut management allows for the silent execution of commands that most detection systems fail to detect. UNC6384 quickly adopted the ZDI-CAN-25373 within just six months of its public disclosure in March 2025, demonstrating exceptional operational agility and vulnerability tracking capabilities.

Arctic Wolf analysts detected the malware after the second paragraph of the research, noting the sophisticated infection mechanism that creates a complex multi-stage attack chain designed to evade traditional security defenses. The exploit mechanism cleverly takes advantage of the addition of whitespaces in the COMMAND_LINE_ARGUMENTS of the LNK file to hide the malicious commands from the user's view.

See also: XWiki: RCE vulnerability used to deliver cryptominer

Hackers exploit RCE vulnerability via Windows LNK files

When executed, the compromised shortcut silently calls PowerShell to extract and unzip a tar file containing three critical components: a legitimate, digitally signed Canon printer utility, a malicious DLL loader, and an encrypted PlugX. The attack chain uses DLL loading, exploiting standard Windows library lookup procedures. When the Canon executable is launched, it instinctively looks for supporting libraries in its local directory before checking system folders.

The malicious DLL located there is transparently loaded, then decrypts the PlugX payload using an embedded RC4 key and injects it directly into the memory space of the legitimate process, creating a nearly undetectable persistent backdoor. The PlugX malware establishes encrypted HTTPS command and control connections using random parameters to multiple fallback domains, such as racineupci[.]org and dorareco[.]net.

See also: Dolby Digital Plus: Vulnerability allows RCE attack

Hackers exploit RCE vulnerability via Windows LNK files

The malware creates hidden persistence directories with fake names such as “SamsungDriver” and modifies Windows registry execution keys, ensuring continued access across system reboots. This campaign demonstrates a level of state-level sophistication, combining zero-day exploit knowledge with meticulous social engineering targeting specific diplomatic personnel and events, representing a significant intelligence gathering threat to European government operations.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS