A critical security vulnerability in Microsoft Windows has been exploited by 11 state-sponsored hacking groups from China, Iran, North Korea, and Russia over the past seven years. The zero-day flaw, identified as ZDI-CAN-25373 by Trend Micro’s Zero Day Initiative, enables attackers to execute hidden malicious commands through specially crafted Windows Shortcut (.LNK) files.
“The attacks leverage hidden command line arguments within .LNK files to execute malicious payloads, complicating detection,” explained researchers Peter Girnus and Aliakbar Zahravi. The exploitation technique involves padding command arguments with Line Feed and Carriage Return characters to bypass security controls.
Nearly 1,000 malicious .LNK files exploiting this vulnerability have been discovered, primarily linked to notorious threat actors including Evil Corp, Kimsuky, Konni, Bitter, and ScarCruft. North Korean hackers represent almost half of the identified state-sponsored groups abusing this flaw, suggesting collaboration among Pyongyang’s cyber units.
The attacks have primarily targeted governments, financial organizations, think tanks, telecommunications providers, and military agencies across the United States, Canada, Russia, South Korea, Vietnam, and Brazil. These malicious .LNK files have been used to deliver various malware including Lumma Stealer, GuLoader, and Remcos RAT, with Evil Corp notably using the vulnerability to distribute Raspberry Robin.
Despite the widespread exploitation, Microsoft has classified the issue as low severity and does not plan to release a patch. The researchers categorize the vulnerability as a “UI Misrepresentation of Critical Information” (CWE-451), explaining that “the Windows UI failed to present the user with critical information” about commands being executed, preventing users from properly evaluating file risk levels.
