Cyber spies linked to the Chinese government exploited a Windows shortcut vulnerability disclosed in March – but that Microsoft hasn't fixed yet – to target European diplomats in an effort to steal defense and national security details. Security firm Arctic Wolf attributed the espionage campaign to UNC6384 (aka Mustang Panda, Twill Typhoon), and in research published Thursday detailed how the suspected PRC spies used social engineering and the Windows flaw to deploy PlugX malware against personnel attending diplomatic conferences in September and October. "This campaign demonstrates UNC6384's capability for rapid vulnerability adoption within six months of public disclosure, advanced social engineering leveraging detailed knowledge of diplomatic calendars and event themes, and operational expansion from traditional Southeast Asia targeting to European diplomatic entities," the Arctic Wolf Labs threat research team said. UNC6384 is a suspected Beijing-backed crew that, according to Google's Threat Intelligence Group, targeted diplomats in Southeast Asia earlier this year before ultimately deploying the PlugX backdoor – a long-time favorite of Beijing-backed goon squads that allows them to remotely access and control infected machines, steal files, and deploy additional malware. In its latest campaign, UNC6384 targeted diplomats in Belgium, Hungary, Italy, and the Netherlands, along with Serbian government aviation departments during September and October 2025, according to Arc...
Suspected Chinese snoops weaponize unpatched Windows flaw
The Register
·Jessica Lyons
·Published Oct 30, 2025
·Updated
Affected Software
1 affected component
Microsoft Windows
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how suspected Chinese spies exploited an unpatched Windows vulnerability to target European diplomats.
2
What security implications are discussed in the article?
The article highlights the risks posed by unpatched vulnerabilities and the potential for espionage against national security.
3
What software is affected according to the article?
The affected software mentioned in the article is Microsoft Windows.
4
What type of vulnerability is being exploited?
The vulnerability being exploited is a Windows shortcut flaw that was disclosed but remains unpatched.
5
Who is believed to be behind the cyber espionage activities mentioned?
The cyber espionage activities are believed to be linked to the Chinese government.