By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Unpatched Windows Zero-Day Flaw Exploited by 11 State-Sponsored Threat Groups Since 2017
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Unpatched Windows Zero-Day Flaw Exploited by 11 State-Sponsored Threat Groups Since 2017
Tech News

Unpatched Windows Zero-Day Flaw Exploited by 11 State-Sponsored Threat Groups Since 2017

By Viral Trending Content 3 Min Read
Share
SHARE

Mar 18, 2025Ravie LakshmananVulnerability / Windows Security

Windows Zero-Day Flaw

An unpatched security flaw impacting Microsoft Windows has been exploited by 11 state-sponsored groups from China, Iran, North Korea, and Russia as part of data theft, espionage, and financially motivated campaigns that date back to 2017.

The zero-day vulnerability, tracked by Trend Micro’s Zero Day Initiative (ZDI) as ZDI-CAN-25373, refers to an issue that allows bad actors to execute hidden malicious commands on a victim’s machine by leveraging crafted Windows Shortcut or Shell Link (.LNK) files.

“The attacks leverage hidden command line arguments within .LNK files to execute malicious payloads, complicating detection,” security researchers Peter Girnus and Aliakbar Zahravi said in an analysis shared with The Hacker News. “The exploitation of ZDI-CAN-25373 exposes organizations to significant risks of data theft and cyber espionage.”

Cybersecurity

Specifically, this involves the padding of the arguments with Line Feed (x0A) and Carriage Return (x0D) characters to evade detection.

Nearly a 1,000 .LNK file artifacts exploiting ZDI-CAN-25373 have been unearthed to date, with a majority of the samples linked to Evil Corp (Water Asena), Kimsuky (Earth Kumiho), Konni (Earth Imp), Bitter (Earth Anansi), and ScarCruft (Earth Manticore).

Of the 11 state-sponsored threat actors that have been found abusing the flaw, nearly half of them originate from North Korea. Besides exploiting the flaw at various times, the finding serves as an indication of cross-collaboration among the different threat clusters operating within Pyongyang’s cyber apparatus.

Telemetry data indicates that governments, private entities, financial organizations, think tanks, telecommunication service providers, and military/defense agencies located in the United States, Canada, Russia, South Korea, Vietnam, and Brazil have become the primary targets of attacks exploiting the vulnerability.

In the attacks dissected by ZDI, the .LNK files act as a delivery vehicle for known malware families like Lumma Stealer, GuLoader, and Remcos RAT, among others. Notable among these campaigns is the exploitation of ZDI-CAN-25373 by Evil Corp to distribute Raspberry Robin.

Cybersecurity

Microsoft, for its part, has classified the issue as low severity and does not plan to release a fix.

“ZDI-CAN-25373 is an example of (User Interface (UI) Misrepresentation of Critical Information (CWE-451),” the researchers said. “This means that the Windows UI failed to present the user with critical information.”

“By exploiting ZDI-CAN-25373, the threat actor can prevent the end user from viewing critical information (commands being executed) related to evaluating the risk level of the file.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

What Is a Preamp, and Do I Really Need One?

Your guide to complete visibility

How do you dispose of old batteries? Derry Cronin, Business Development Director of EHS International

CSA Issues Alert on Critical SmarterMail Bug Allowing Remote Code Execution

Vodafone Foundation and Rethink Ireland announce recipients of €540,000 Fund to Boost Digital Literacy for Older Adults

TAGGED: cyber espionage, Cyber Security, Cybersecurity, data breach, Internet, Malware, Microsoft, State-Sponsored Attack, Vulnerability, windows security, Zero-Day
Share This Article
Facebook Twitter Copy Link
Previous Article The best Humble deal is exclusive to viraltrendingcontent readers
Next Article Federal judge blocks Trump administration from banning transgender people from military service
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

John F. Kennedy’s Grandchildren: See Photos of Rose, Tatiana & Jack Schlossberg
Celebrity
Metal Gear Solid Delta: Snake Eater is a Love Letter to Action Cinema
Gaming News
ChatGPT thinks these are the 5 best FTSE stocks to consider buying for 2026!
Business
The Separation: Inside the Unraveling U.S.-Ukraine Partnership
World News
Idaho company recalls nearly 3,000 pounds of ground beef for E. coli risk
Business
What Is a Preamp, and Do I Really Need One?
Tech News
Your guide to complete visibility
Tech News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

ChatGPT thinks these are the 5 best FTSE stocks to consider buying for 2026!

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
ChatGPT thinks these are the 5 best FTSE stocks to consider buying for 2026!
December 30, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?