UNC6384 Targets European Diplomacy with LNK Vulnerability

31 Oct 2025

Between September and October 2025, the threat actor group UNC6384 launched attacks using a Windows shortcut (LNK) vulnerability to target European diplomatic and government entities. The primary targets included diplomatic organizations in Hungary, Belgium, Italy, and the Netherlands, as well as government agencies in Serbia.

Attack Techniques and Targets

The campaign began with spear-phishing emails embedding URLs that led to malicious LNK files. These files, themed around European diplomatic meetings and workshops, exploited the vulnerability identified as ZDI-CAN-25373. The targeted entities are heavily involved in defense cooperation and policy coordination. The malicious LNK files trigger a chain that ends with DLL sideloading to deploy the PlugX malware. Google Threat Intelligence Group noted some overlap between UNC6384 and Mustang Panda.

The attack utilized LNKs to initiate a PowerShell command, which decoded and extracted a TAR archive, presenting a decoy PDF. The archive included a legitimate utility and a malicious DLL, CanonStager, which sideloads an encrypted PlugX payload. This payload provides remote access capabilities, supporting operations such as command execution and file manipulation.

Development and Mitigation

Arctic Wolf reported that artifacts related to CanonStager were reduced in size from approximately 700 KB to 4 KB during this period, suggesting ongoing development aimed at reducing forensic footprints. Additional tactics included the use of HTA files to load JavaScript from cloudfront.net domains. Microsoft noted Defender and Smart AppControl protections can mitigate risks associated with such malicious files.

The initial report of the LNK vulnerability was made by Peter Girnus and Aliakbar Zahravi in March 2025. The strategic focus of the attacks aligns with China’s intelligence requirements, specifically around European alliance and policy cohesion.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6309701
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1240674
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
488962
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
452416
downloads

News and reviews for Desktop Windows

Launch Humble Bundle's Indie Horror Pack for Halloween Thriller

Humble Bundle launches Indie Fears Bundle for Halloween, featuring 13 horror games like Mouthwashing. Available globally, ends 2025-11-20.

Read more

UNC6384 Targets European Diplomacy with LNK Vulnerability

UNC6384 exploited an LNK vulnerability, impacting European diplomatic bodies in late 2025.

Read more

Arc Raiders Launches with Discount on Fanatical

Arc Raiders, by Embark Studios, launched 2025-10-30. Available at 14% discount on Fanatical. Unique approach to extraction shooter genre.

Read more

Fear Effect 2: Retro Helix Launches on Modern Platforms in 2026

Fear Effect 2: Retro Helix lands on PlayStation, Switch, and PC in 2026, expanding its reach to modern platforms.

Read more

Escape From Tarkov Launches Final Version, Expands to Steam

Escape From Tarkov's final version releases on 2025-11-15, including Steam availability for a broader audience.

Read more

Access Free Loadouts in Arc Raiders

Players can now access free loadouts in Arc Raiders for easy early missions, enhancing gameplay without risking valuable gear.

Read more

Creates Windows 7 Install at 69MB

Veteran Windows Insider develops a 69MB Windows 7 install. Though bootable, key files are missing, limiting functionality.

Read more

Wordle Puzzle 1595: October 31, 2025, Solution Revealed

The solution to Wordle puzzle 1595 for October 31, 2025, is unveiled as 'ABHOR'. The word features two vowels and begins with an A.

Read more

Launch of MR Link by Microsoft and Meta Transforms Workspaces

Microsoft and Meta release MR Link for Quest headsets, enhancing mixed-reality productivity. This innovation could reduce multi-monitor costs.

Read more

KusoDungeon Name Error Boosts Game Awareness

Paolo Nicoletti's misnamed game, KusoDungeon, quickly gained attention for its humor and retro feel.

Read more