Windows LNK Vulnerability Exploited in Geopolitical Cyberattacks

31 Oct 2025

A critical vulnerability in Windows LNK files, designated ZDI-CAN-25373, has been exploited by cyberespionage groups globally for executing hidden commands. This vulnerability allows attackers to use whitespace padding to obscure malicious PowerShell scripts in shortcut files, posing a significant threat to data security.

Technical Exploit Details

Attackers utilize LNK files with diplomatic-themed names to remotely execute concealed PowerShell commands. These commands decode embedded TAR archives within the shortcut files, which contain three key components loaded via DLL sideloading. The components include a signed Canon utility (cnmpaui.exe), a malicious loader DLL (cnmpaui.dll), and an RC4-encrypted payload (cnmplog.dat), which constitutes a remote access trojan.

The DLL search order in Windows allows the signed executable to load the malicious DLL. The payload is decrypted using a hardcoded 16-byte RC4 key, enabling it to execute within a trusted process, even with an expired certificate timestamped as valid. The command-and-control infrastructure uses domains such as racineupci[.]org and dorareco[.]net.

Recommendations and Mitigations

Mitigation strategies include disabling automatic LNK file resolution, blocking known command-and-control domains at network edges, and monitoring execution of Canon utilities from unexpected directories. Enhanced surveillance is necessary for potential targets, including government and diplomatic entities, as this vulnerability remains unpatched by Microsoft as of 2025-10-31.

Security experts recommend proactive threat hunting and vigilant monitoring of LNK file activities to prevent exploitation and data leaks.

Windows PowerShell

Windows PowerShell download for free to PC or mobile

Latest update Windows PowerShell download for free for Windows PC or Android mobile

2
887 reviews
2479 downloads

News and reviews about Windows PowerShell

31 Oct 2025

Windows LNK Vulnerability Exploited in Geopolitical Cyberattacks

ZDI-CAN-25373 LNK vulnerability lets attackers execute hidden PowerShell commands. Threats target data and intelligence globally.

Read more

21 Oct 2025

PowerShell Gains Edge Over Bash on Windows

PowerShell, with its object-based output and OS integration, surpasses Bash for Windows admin.

Read more

07 Oct 2025

Methods to Turn Off Display Without Sleep Mode

Explore innovative ways to switch off your computer display in Windows without triggering sleep mode. From PowerShell commands to third-party utilities, discover practical solutions.

Read more

16 Sep 2025

PowerShell Unveils Hidden Windows Features

Discover Windows features unlocked by PowerShell beyond its GUI, showcasing enhanced productivity and cybersecurity.

Read more

11 Sep 2025

Windows 11 Update Removes Obsolete Tools for Security

The latest Windows 11 update deletes PowerShell 2.0 and WMIC due to security concerns, urging users to adopt newer versions. Microsoft prepares systems for upcoming enhancements.

Read more

26 Aug 2025

Microsoft to Remove PowerShell 2.0 from Windows by 2025

Microsoft will phase out PowerShell 2.0 from Windows 11 and Windows Server in 2025. Users are encouraged to transition to PowerShell 5.1 or 7.

Read more

17 May 2025

PowerShell Exploitation Sparks New Cybersecurity Concerns

Threat actors increasingly use PowerShell for bypassing advanced antivirus and EDR solutions. This technique, known as Living off the Land, poses significant cybersecurity risks. Security teams are urged to enhance threat detection with strict application measures and PowerShell logging.

Read more

04 Mar 2025

Understanding the Role of Windows Services in Systems

Explore Windows services through tools like Daemon Master for effective management and troubleshooting. Learn to navigate Computer Management for system optimization.

Read more

04 Mar 2025

Malware Threats Exploit Microsoft Tools, Demand New Measures

Experts report increasing fileless malware attacks using PowerShell and Microsoft apps, complicating detection. Multi-layered cybersecurity measures, such as enhanced PowerShell logging and Endpoint Detection, are recommended.

Read more

20 Aug 2024

PowerShell 7.4 Enhances Cross-Platform Automation for System Administrators

PowerShell, a versatile command-line interface and scripting language by Microsoft, is now open-source and cross-platform, supporting Windows, macOS, and Linux. The latest version, 7.4, built on .NET Core, offers advanced automation for system administrators. Installation options include GitHub and Microsoft Store.

Read more