Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Chinese APT Exploits Unpatched Windows Flaw in Recent Attacks

Posted on October 31, 2025October 31, 2025 By CWS

A Chinese language risk actor has been exploiting an unpatched Home windows shortcut vulnerability in recent assaults concentrating on the diplomatic neighborhood in Europe, Arctic Wolf stories.

The exploited flaw, tracked as CVE-2025-9491 (CVSS rating of seven.0), is described as a UI misrepresentation problem, as Home windows fails to point out important data (which may present proof of malicious exercise) when the person inspects the file’s properties.

The assaults seen by Arctic Wolf contain the distribution of LNK information designed to execute malicious code when opened by the sufferer. CVE-2025-9491 is exploited to make the malicious code invisible to a person who could take a look at the file’s properties.  

Development Micro’s Zero Day Initiative (ZDI) reported the problem to Microsoft in September 2024. Microsoft has not launched patches for the safety defect, notifying ZDI that the problem doesn’t meet the bar for servicing. In step with its disclosure coverage, ZDI launched data on the vulnerability in March this yr.

ZDI warned on the time that 11 state-sponsored APT teams from North Korea, Russia, China, and Iran have been abusing specifically crafted LNK information in assaults concentrating on protection, vitality, monetary, authorities, army, telecoms, assume tank, and personal organizations.

Microsoft informed SecurityWeek in March that customers not often examine a file’s properties to search for malicious code and Microsoft Defender is able to detecting using this system in LNK information. 

The tech large additionally famous that making an attempt to open such a file that was downloaded from the web routinely triggers a safety warning, and stated customers ought to train warning when opening information fetched from the web or obtained from untrusted sources.

Now, Arctic Wolf says that UNC6384, a Chinese language risk actor linked to the Mustang Panda APT, which can also be tracked as Basin, Bronze President, Earth Preta, Purple Delta, Temp.Hex, and Twill Hurricane, has been exploiting CVE-2025-9491 in assaults since September 2025.Commercial. Scroll to proceed studying.

The hacking group has been concentrating on European diplomats with spear-phishing emails containing an embedded URL that initiates an an infection chain resulting in the supply of the PlugX distant entry trojan (RAT).

At one stage within the an infection chain, “malicious LNK information themed round European Fee conferences, NATO-related workshops, and multilateral diplomatic coordination occasions” are dropped to use the unpatched vulnerability.

The exploit permits UNC6384 to execute PowerShell instructions, drop a signed Canon printer utility, and abuse it to execute PlugX through DLL sideloading.

“Arctic Wolf Labs assesses with excessive confidence that this marketing campaign is attributable to UNC6384. This attribution relies on a number of converging strains of proof together with malware tooling, tactical procedures, concentrating on alignment, and infrastructure overlaps with beforehand documented UNC6384 operations,” the cybersecurity agency notes.

In September and October, Arctic Wolf noticed UNC6384 exploiting the bug in assaults geared toward Hungarian and Belgian diplomatic personnel. Moreover, the corporate linked the marketing campaign with the concentrating on of Serbian authorities aviation departments and diplomatic entities in Italy and the Netherlands.

Associated: Chinese language APT ‘Phantom Taurus’ Focusing on Organizations With Internet-Star Malware

Associated: Chinese language Cyberspies Hacked US Protection Contractors

Associated: Chinese language Hackers Lurked Almost 400 Days in Networks With Stealthy BrickStorm Malware

Associated: Particulars Emerge on Chinese language Hacking Operation Impersonating US Lawmaker

Security Week News Tags:APT, Attacks, Chinese, Exploits, Flaw, Unpatched, Windows

Post navigation

Previous Post: Threat Actors Actively Using Open-Source C2 Framework to Deliver Malicious Payloads
Next Post: Jamf to Go Private Following $2.2 Billion Acquisition by Francisco Partners

Related Posts

SBOM Pioneer Allan Friedman Joins NetRise to Advance Supply Chain Visibility Security Week News
Airoha Chip Vulnerabilities Expose Headphones to Takeover Security Week News
Oracle Patches 200 Vulnerabilities With July 2025 CPU Security Week News
Guardz Banks $56M Series B for All-in-One SMB Security Security Week News
Dux Emerges From Stealth Mode With $9 Million in Funding Security Week News
In Other News: 600k Hit by Healthcare Breaches, Major ShinyHunters Hacks, DeepSeek’s Coding Bias Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware
  • UEFI Vulnerability in Major Motherboards Enables Early-Boot Attacks
  • HPE Patches Critical Flaw in IT Infrastructure Management Software
  • HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution
  • CISA Adds ASUS Embedded Malicious Code Vulnerability to KEV List Following Active Exploitation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware
  • UEFI Vulnerability in Major Motherboards Enables Early-Boot Attacks
  • HPE Patches Critical Flaw in IT Infrastructure Management Software
  • HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution
  • CISA Adds ASUS Embedded Malicious Code Vulnerability to KEV List Following Active Exploitation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark