UNC6384 Targets European Diplomacy with LNK Vulnerability

31 Oct 2025

Between September and October 2025, the threat actor group UNC6384 launched attacks using a Windows shortcut (LNK) vulnerability to target European diplomatic and government entities. The primary targets included diplomatic organizations in Hungary, Belgium, Italy, and the Netherlands, as well as government agencies in Serbia.

Attack Techniques and Targets

The campaign began with spear-phishing emails embedding URLs that led to malicious LNK files. These files, themed around European diplomatic meetings and workshops, exploited the vulnerability identified as ZDI-CAN-25373. The targeted entities are heavily involved in defense cooperation and policy coordination. The malicious LNK files trigger a chain that ends with DLL sideloading to deploy the PlugX malware. Google Threat Intelligence Group noted some overlap between UNC6384 and Mustang Panda.

The attack utilized LNKs to initiate a PowerShell command, which decoded and extracted a TAR archive, presenting a decoy PDF. The archive included a legitimate utility and a malicious DLL, CanonStager, which sideloads an encrypted PlugX payload. This payload provides remote access capabilities, supporting operations such as command execution and file manipulation.

Development and Mitigation

Arctic Wolf reported that artifacts related to CanonStager were reduced in size from approximately 700 KB to 4 KB during this period, suggesting ongoing development aimed at reducing forensic footprints. Additional tactics included the use of HTA files to load JavaScript from cloudfront.net domains. Microsoft noted Defender and Smart AppControl protections can mitigate risks associated with such malicious files.

The initial report of the LNK vulnerability was made by Peter Girnus and Aliakbar Zahravi in March 2025. The strategic focus of the attacks aligns with China’s intelligence requirements, specifically around European alliance and policy cohesion.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6339225
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1250879
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
492538
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
452982
downloads

News and reviews for Desktop Windows

Mortal Kombat: Legacy Kollection Faces Early Challenges on Steam

Mortal Kombat: Legacy Kollection launched on Steam with issues, including input lag and online problems. Patches are underway to address concerns.

Read more

Arc Raiders Strains Under Surge of Players

Arc Raiders faces login queues and matchmaking issues as concurrent players spike to 337,834.

Read more

Flyoobe Users Alerted to Potential Malware via Fake Site

Flyoobe users advised to avoid fake site amid security risks. Verify downloads from official channels to prevent malware.

Read more

Diablo 2 Update: New Ammo Types Enhance Ranged Combat

Project Diablo 2 Season 12 adds diverse ammo types, enhancing ranged combat with arrows and bolts. Date to be confirmed during November 8 stream.

Read more

Resonance Solstice Faces Mixed Reviews at Launch

Resonance Solstice, a free Steam game, launched with mixed feedback. Player concerns focus on complex currencies and gameplay mechanics.

Read more

Thief VR Set for December Release with Promising Features

Thief VR: Legacy of Shadow, launching 2025-12-04, introduces new protagonist Magpie with immersive gameplay changes.

Read more

EDR-Redir V2 Bypasses Windows Defender with Redirection Loops

EDR-Redir V2 uses fake program files to evade Windows Defender on Windows 11, exploiting directory redirection tactics.

Read more

Office 2021 Lifetime License Discounted to $39.97

For a limited time, purchase Office 2021 for $39.97, a significant discount from its usual $219.99 price.

Read more

Spooky Express Update Brings Over 200 New Levels

Spooky Express, by Draknek and Friends, expands Cosmic Express with 200+ levels, now on Steam.

Read more

Skinballs Preserved by Strong Museum for Future Study

The Strong Museum has preserved Skinballs, a Saints Row test NPC, for future study and preservation, enhancing gaming history.

Read more