A severe Windows zero-day vulnerability, active since at least 2017, is being used by state-backed hackers from North Korea, China, Iran, and Russia. Despite its long-running exploitation across various industries and nations, the flaw still remains unpatched.

Tracked as ZDI-CAN-25373 by Trend Micro’s Zero Day Initiative (ZDI), the flaw allows attackers to use specially crafted .LNK files — commonly known as Windows shortcuts — to run harmful commands without alerting the user. What’s more troubling is that Microsoft has classified it as low priority and has no immediate plans to fix it.

A Silent Danger Hidden in Everyday Files

How a Simple Shortcut Becomes a Threat

The attack method is as clever as it is quiet. Hackers embed hidden commands inside .LNK files, using whitespace characters like tabs and spaces to mask malicious instructions from antivirus tools.

This allows them to run malware on a system without the user even realizing it. These disguised shortcuts look completely normal, yet they secretly trigger harmful programs when clicked.

A Flaw That Skips the User’s Warning System

What makes this issue more dangerous is that it bypasses visual warnings. According to security experts from ZDI, the Windows interface fails to alert users that a hidden command is being executed, which means users cannot judge whether the shortcut file is safe or suspicious.

This lack of visibility is what places the flaw under a classification called User Interface Misrepresentation, also known as CWE-451.

Eleven Advanced Threat Groups Exploit the Flaw

Attacks from Four Major Nations

Over the years, at least 11 state-sponsored threat actors have taken advantage of this vulnerability. Most notably, the groups originate from:

  • North Korea
  • China
  • Iran
  • Russia

Researchers found strong evidence that North Korean cyber groups are working together to share tools and strategies, with multiple attacks pointing to joint operations under different codenames like Kimsuky, Konni, and ScarCruft.

Not Just One Malware Family

Once the hidden shortcut is activated, it can deliver various kinds of malware, including:

  • Lumma Stealer
  • GuLoader
  • Remcos RAT
  • Raspberry Robin, used by Evil Corp

These malware programs are known for stealing information, spying on victims, or creating remote access paths for attackers to control infected machines.

Global Impact: From Governments to Private Sectors

Victims Across Six Nations

This vulnerability is not a small-scale threat. ZDI found that it has been used to target major industries and sectors in:

  • The United States
  • Canada
  • Russia
  • South Korea
  • Vietnam
  • Brazil

Affected organizations include government bodies, military departments, telecommunication companies, think tanks, and financial institutions.

Almost 1,000 Malicious Files Found

Since tracking began, researchers have uncovered nearly 1,000 different .LNK files exploiting this zero-day. Each one is slightly unique, customized by different threat groups to avoid detection.

This points to an active, long-term strategy where attackers evolve their tools but keep using the same weak point — a shortcut file that nobody expects to be dangerous.

Microsoft’s Position and Security Measures

Why the Flaw Remains Unpatched

In response to the findings, Microsoft acknowledged the report and thanked ZDI for following a coordinated disclosure process. However, they stated that the flaw does not meet the severity level required for immediate patching.

Instead, Microsoft is relying on existing tools like:

  • Microsoft Defender, which scans and blocks malicious content
  • Smart App Control, which warns users when unknown files are opened
  • File type restrictions in products like Outlook, Excel, and OneNote, which block .LNK files from opening directly

Limited Use According to Microsoft

Microsoft further emphasized that this technique has limited use in real-world attacks, and that Defender’s scanning capabilities are already equipped to detect it.

Even so, cybersecurity experts argue that the ongoing use of the flaw by sophisticated actors shows that it still presents a real and present risk to organizations, especially when layered into broader attack chains.

Why This Vulnerability Is Still Being Used

A Reliable Entry Point for Spies and Cybercriminals

From a hacker’s perspective, ZDI-CAN-25373 is a perfect tool:

  • It’s easy to embed in common file types
  • It doesn’t require advanced code to activate
  • It hides in plain sight, with minimal user interaction
  • It works on any version of Windows that handles .LNK files

And since it remains unpatched, there’s no technical reason for attackers to stop using it.

As long as Windows continues to process shortcut files the same way, and users continue to open them without suspicion, this vulnerability will remain a quiet threat lurking inside inboxes, folders, and download directories.

Best Practices for Protecting Against .LNK-Based Attacks

Simple Actions Can Block a Complex Threat

While waiting for a permanent fix, security teams and individuals can still take action. Here’s how:

  • Do not open shortcut files from unknown sources
  • Disable automatic file execution features where possible
  • Train employees to recognize suspicious file types
  • Use endpoint detection and response (EDR) tools to scan for hidden scripts
  • Keep antivirus tools updated and active at all times
  • Restrict .LNK execution in secure environments, especially in shared drives

For organizations in sensitive sectors like defense or telecom, these steps could block a major entry point that advanced threat actors have been using for years.

FAQs

What is ZDI-CAN-25373?
It is a Windows zero-day vulnerability involving .LNK files that can hide malicious commands, allowing attackers to run malware without user consent.

Who is using this flaw?
At least 11 state-sponsored hacker groups from countries like North Korea, China, Iran, and Russia have used it in real-world attacks since 2017.

What kind of malware can be delivered through this flaw?
Malware like Lumma Stealer, GuLoader, Remcos RAT, and Raspberry Robin can be delivered using this method.

Has Microsoft fixed the flaw?
No. Microsoft considers it low severity and has not released a patch. They recommend relying on built-in tools like Defender and Smart App Control.

What makes this flaw hard to detect?
The attack uses hidden characters in shortcut files and avoids showing warning messages to the user, making it difficult for both people and security tools to spot.

How can I stay protected?
Avoid unknown shortcut files, keep your antivirus updated, train users to identify suspicious files, and consider using EDR solutions for added protection.

Author

Share.

198 Comments

  1. [8251]Panaloko Online Casino: Best Philippines slots and gaming. Easy Panaloko login, register, and official app download for an elite experience. Join Panaloko Online Casino, the Philippines’ top destination for elite slots. Easy Panaloko login, quick Panaloko register, and official Panaloko app download for a premium gaming experience. Play the best Panaloko online casino games today! visit: panaloko

  2. Yo, jl18login! Finally got around to logging in. The process was smooth as butter—no hiccups at all. Seems like they’ve really streamlined things. Give it a whirl and see for yourself! More adventures await at jl18login.

  3. Alright, mv888 came through with the goods. Easy to get around, and the whole setup feels professional. Gonna keep this one on my radar! Go see what it’s all about at mv888.

  4. Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?

  5. Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?

  6. Hey guys, trying out x03bet. Not bad at all! The options are solid and the navigation’s smooth. Hoping I can snag a win! Check them out here: x03bet.

  7. Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?

  8. Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?

  9. I don’t think the title of your article matches the content lol. Just kidding, mainly because I had some doubts after reading the article.

  10. Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?

  11. Came in for one specific question and got answers to three I had not even thought to ask, and a look at firstisnotequallast extended that bonus value pattern, the kind of resource that anticipates reader needs rather than just answering the literal question asked is the gold standard and this site reaches it.

  12. Hello my friend! I wish to say that this post is amazing, nice written and come with almost all significant infos. I would like to see more posts like this .

  13. Mầm non nụ cười thông tây hội của vấn đề này không hề nhỏ chút nào. Windows Zero-Day Flaw Exploited by 11 State Groups Since 2017 Remains Unpatched – Ambreen Chaudhary Mở đầu bài viết, tôi đã bị sốc khi đọc về việc 11 quốc gia đang sử dụng mã hóa đặc biệt để khơi dậy một lỗ hổng trong hệ thống Windows. use Skips

  14. Jamie weylad secretly on

    It’s concerning to learn that state-backed hackers have been using these shortcuts to wreak havoc without alerting users. The fact that Microsoft hasn’t prioritized fixing this issue is a huge oversight, considering the impact it could have on security and privacy. This mầm non đồng nai situation needs immediate attention from all stakeholders involved in cybersecurity. secretly government

  15. Đọc bài viết này về Windows Zero-Day Flaw Remains Unpatched đã khiến tôi nhớ đến những năm tháng trước kia, khi tôi chọn trường Mần Non Sài Gòn để theo học. Thời gian đó, tôi thường xuyên phải đối mặt với những rủi ro từ sự cố hệ thống nhỏ lẻ và những vấn đề về bảo mật không ngờ. judge exploiting

  16. The article really brought to light how critical it is for us all to prioritize cybersecurity and patch our systems quickly. Sổ tay mầm non đà nẵng, Microsoft’s negligence with this zero-day flaw highlights just how vulnerable our technology can be if not kept up-to-date properly. Despite the severe consequences of such a vulnerability being exploited by state-backed hackers from around the world, it remains unpatched and ignored by Microsoft. Private yet

  17. What really concerns me is that the classification as “low priority” and no immediate fix only serves to encourage even more malicious activity. I hope this warning will finally prompt Microsoft to address this issue before any more critical information or assets are compromised. The implications of such a breach could be catastrophic, so it’s imperative that we hold them accountable for their negligence. Mầm non hà nội. found uncovered

  18. Trường học phía nam không thể có một lớp học mà thiếu đi giáo trình về internet safety và cách phòng ngừa những mối đe dọa như zero-day flaw. Điều này rất quan trọng vì không chỉ là vấn đề riêng cho các trường học, mà còn liên quan đến việc bảo vệ nền tảng học tập của mỗi thế hệ con người hiện nay. long Close

  19. Giáo dục miền bắc Càng lớn lên và nhìn lại những năm tháng ngồi trên ghế nhà trường, mình càng thấy nể phục sự nghiêm khắc nhưng cũng đầy tâm huyết của các thầy cô ngoài này. Dù đôi lúc cách truyền đạt có phần khuôn mẫu, nhưng chính sự chỉn chu và nền nếp ấy đã rèn giũa cho mình một tư duy rất vững vàng và kỷ luật. Có lẽ phải đi xa rồi mới thấy trân trọng những giá trị cốt lõi mà môi trường giáo dục miền Bắc đã bồi đắp, giúp mình có được hành trang tự tin để bước vào đời. Hy vọng rằng trong tương lai, dù thay đổi thế nào thì cái chất “tôn sư trọng đạo” vốn có vẫn luôn được giữ gìn và phát huy. Pinterest bodies

  20. Mầm chòi lá thật là một vấn đề nghiêm trọng khi Windows Zero-Day Flaw vẫn không được cập nhật. Mặc dù Microsoft đã biết về nó từ lâu nhưng họ chỉ coi nó như là một lỗi trung bình và không có kế hoạch để khắc phục. Điều này cho thấy sự thiếu trách nhiệm và cam kết bảo vệ hệ điều hành của chúng ta. instructions Stake

  21. Trước cổng trường, thật là lo lắng khi đọc thông tin này. Windows Zero-Day Flaw Exploited by 11 State Groups Since 2017 Remains Unpatched – Ambreen Chaudhary. Mặc dù công ty Microsoft đã công bố lỗi và yêu cầu cập nhật nhanh chóng để giảm thiểu nguy cơ, nhưng vấn đề vẫn chưa được giải quyết. This departments

  22. It’s scary how state-sponsored hackers are using Windows shortcuts to exploit zero-day vulnerabilities. But it’s frustrating that Microsoft hasn’t fixed this for years. I hope they take swift action to patch this flaw before more organizations get compromised. Việt Nam PreSchool Réources, just one of the 10 Vietnamese students who participated in a recent cybersecurity competition organized by our local Ministry of Education and Training. Mins Massive

  23. Điều này cho thấy việc quản lý của Microsoft vẫn còn cần cải thiện ở nhiều nơi, đặc biệt là trong việc bảo vệ người dùng khỏi các mối đe dọa tiềm tàng như vậy. Mầm non việt nam luôn tồn tại, và tôi tin rằng thông qua những hiểu biết sâu sắc về vấn đề này, chúng ta có thể tìm ra cách để ngăn chặn nó hơn nữa. Progressive vulnerability

  24. Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?

  25. I’ve been looking for a reliable spot like this for a while. The interface is super smooth and the payouts are legit. Definitely checking out idarya88 more often now!

  26. Virtually all of what you say is astonishingly accurate and that makes me wonder the reason why I had not looked at this with this light before. This particular article truly did switch the light on for me as far as this issue goes. But there is actually just one factor I am not too cozy with so while I try to reconcile that with the central theme of the issue, permit me see what all the rest of your visitors have to point out.Nicely done.

  27. Really impressed with the variety of games here. Everything loads quickly and the customer support is actually helpful. Definitely recommend 25sbet for anyone starting out.

Leave A Reply

© 2026 ThemeSphere. Designed by ThemeSphere.
Exit mobile version