A China-linked hacking group is exploiting a Windows zero-day in attacks targeting European diplomats in Hungary, Belgium, and other European nations. According to Arctic Wolf Labs, the attack chain begins with spearphishing emails that lead to the delivery of malicious LNK files themed around NATO defense procurement workshops, European Commission border facilitation meetings, and various other diplomatic events. These malicious files are designed to exploit a high-severity Windows LNK vulnerability (tracked as CVE-2025-9491) to deploy the PlugX remote access trojan (RAT) malware and gain persistence on compromised systems, allowing them to monitor diplomatic communications and steal sensitive data. The cyber-espionage campaign has been attributed to a Chinese state-backed threat group tracked as UNC6384 (Mustang Panda), known for conducting espionage operations aligned with Chinese strategic interests and targeting diplomatic entities across Southeast Asia. Analysis of malware and infrastructure used in this campaign by researchers from Arctic Wolf Labs and StrikeReady has also revealed that these attacks have broadened their scope in recent weeks. While initially focused on Hungarian and Belgian diplomatic entities, they now also target other European organizations, including Serbian government agencies and diplomatic entities from Italy and the Netherlands. "Arctic Wolf Labs assesses with high confidence that this campaign is attributable to UNC6384, a Chinese-affiliated...
Windows zero-day actively exploited to spy on European diplomats
BleepingComputer
·Sergiu Gatlan
·Published Oct 31, 2025
·Updated
Affected Software
1 affected component
Microsoft Windows
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a China-linked hacking group's exploitation of a Windows zero-day vulnerability to spy on European diplomats.
2
What security implications are discussed in the article?
The article highlights the risks associated with zero-day vulnerabilities and the potential impact on diplomatic security.
3
What products or software are affected by the exploits mentioned?
The exploits mentioned in the article specifically target Microsoft Windows.
4
Who are the main targets of these cyber attacks?
The main targets of these cyber attacks are European diplomats in countries such as Hungary and Belgium.
5
What methods are employed by the hackers in these attacks?
The hackers use spearphishing emails that deliver malicious LNK files themed around NATO to initiate their attacks.