Between September and October 2025, a new round of assaults targeting European government and diplomatic institutions have been traced to a China-affiliated threat actor called UNC6384. These attacks take advantage of an unpatched Windows shortcut vulnerability.
According to a technical assessment released Thursday by Arctic Wolf, the operation targeted government entities in Serbia as well as diplomatic organizations in Hungary, Belgium, Italy, and the Netherlands.
According to the cybersecurity firm, the attack chain starts with spear-phishing emails that have an embedded URL. This is the first of multiple steps that culminate in the delivery of malicious LNK files that are themed around meetings of the European Commission, workshops connected to NATO, and events involving multilateral diplomatic coordination.
The files are made to take advantage of ZDI-CAN-25373 in order to start a series of attacks read more about China-Linked Hackers Exploit Windows Shortcut Flaw to Target European Diplomats.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
