Archived

Oct 31, 2025Ravie LakshmananMalware / Threat Intelligence

A China-affiliated threat actor known as UNC6384 has been linked to a fresh set of attacks exploiting an unpatched Windows shortcut vulnerability to target European diplomatic and government entities between September and October 2025.

The activity targeted diplomatic organizations in Hungary, Belgium, Italy, and the Netherlands, as well as government agencies in Serbia, Arctic Wolf said in a technical report published Thursday.

“The attack chain begins with spear-phishing emails containing an embedded URL that is the first of several stages that lead to the delivery of malicious LNK files themed around European Commission meetings, NATO-related workshops, and multilateral diplomatic coordination events,” the cybersecurity company said.

[…]

  • StinkyFingerItchyBum@lemmy.ca
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    12
    ·
    edit-2
    1 month ago

    China based hackers…

    American based too, but we call them Microsoft employees and the American “government”.

      • CosmoNova@lemmy.world
        link
        fedilink
        English
        arrow-up
        9
        arrow-down
        1
        ·
        1 month ago

        The problem we have with you guys is that you always rush to the whataboutism mobile when China is mentioned but we all know you wouldn‘t care in the slightest if it was Japanese hackers for example.

        • StinkyFingerItchyBum@lemmy.ca
          link
          fedilink
          English
          arrow-up
          3
          arrow-down
          2
          ·
          edit-2
          1 month ago

          Not whatabout. And.Chinese hackers are a major threat as is China. China is agressively violating international law in the south China Sea. They are no one’s friend.

          I’m just saying sensitive government functions are compromised by simply using Microsoft. You are compromised before you get hacked.