XDigo Malware Exploits Windows LNK Flaw in Eastern European Government Attacks
In March 2025, cybersecurity experts discovered XDigo, a Go-based malware, utilised in attacks against governmental organisations in Eastern Europe.
According to French cybersecurity firm HarfangLab, the attack chains allegedly used a group of Windows shortcut (LNK) files as part of a multi-step process to spread the malware.
Since 2011, government entities in Eastern Europe and the Balkans have been the subject of cyber espionage known as XDSpy. Early in 2020, the Belarusian CERT published the first documentation about it.
Campaigns to distribute malware families including UTask, XDDown, and DSDownloader—which can download more payloads and steal private data from vulnerable hosts have targeted businesses in Russia and Moldova in recent years read more about XDigo Malware Exploi...

