Executive Summary
In late 2025, the China-linked threat group UNC6384 orchestrated a targeted cyber espionage campaign against European diplomatic and government institutions. Utilizing a previously unpatched Windows shortcut (LNK) vulnerability, attackers delivered malicious payloads to compromise systems in Hungary, Belgium, Italy, the Netherlands, and Serbia. The group specialized in stealthy lateral movement, data collection, and command-and-control operations while evading standard defenses. As a result, sensitive government data and communications were potentially exposed, undermining national security and international collaboration efforts.
This incident underscores the growing sophistication of state-sponsored cyberattacks, intensified by the exploitation of zero-day vulnerabilities and advanced lateral movement techniques. The frequent targeting of government and diplomatic organizations shows a continued evolution in APT tactics and a rising threat to global critical infrastructure.
Why This Matters Now
State-backed attackers are accelerating the use of unpatched vulnerabilities and stealth tactics to target high-value government assets. With diplomatic tensions high and a wave of similar campaigns observed across Europe, organizations must prioritize zero trust, robust segmentation, and rapid incident detection to preempt sustained espionage threats.
Attack Path Analysis
UNC6384 gained initial access by exploiting an unpatched Windows shortcut vulnerability delivered via spearphishing to European diplomatic entities. Following initial compromise, the attackers escalated privileges to obtain broader access to victim environments. They conducted lateral movement by pivoting across internal networks, targeting sensitive government systems and possibly workloads or containers. Command and Control were established using covert, likely encrypted channels to maintain persistence and receive instructions. Large volumes of sensitive data were exfiltrated via outbound channels to attacker-controlled infrastructure. The final impact included data theft, potential espionage, and operational disruption to diplomatic and government operations.
Kill Chain Progression
Initial Compromise
Description
Attackers delivered malicious Windows shortcut files through phishing, exploiting an unpatched LNK vulnerability to infect user endpoints.
Related CVEs
CVE-2025-9491
CVSS 7.8A vulnerability in Windows LNK file handling allows attackers to hide malicious commands within shortcut files, leading to remote code execution when the file is opened.
Affected Products:
Microsoft Windows – 10, 11
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
User Execution: Malicious File
Boot or Logon Autostart Execution: Shortcut Modification
Command and Scripting Interpreter
Phishing: Spearphishing Attachment
Impair Defenses: Disable or Modify Tools
Valid Accounts
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIS2 Directive – Risk Management Measures – Policies and Procedures
Control ID: Article 21(2)(a)
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: Section 500.03
PCI DSS 4.0 – Security Vulnerabilities Addressed
Control ID: Requirement 6.3.1
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Article 9(2)
CISA Zero Trust Maturity Model 2.0 – Continuous Diagnosis and Mitigation
Control ID: Identity – Vulnerability Management
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
European diplomatic and government entities directly targeted by China-linked APT UNC6384 exploiting Windows shortcuts, compromising sensitive diplomatic communications and requiring enhanced zero trust segmentation.
International Affairs
Diplomatic organizations in Hungary, Belgium, Italy, and Netherlands specifically targeted, exposing critical international relations data to advanced persistent threats requiring encrypted traffic protection.
Computer/Network Security
Unpatched Windows vulnerability exploitation demonstrates urgent need for threat detection capabilities, inline IPS deployment, and multicloud visibility to prevent lateral movement in security infrastructure.
Information Technology/IT
Windows shortcut vulnerability affects IT infrastructure globally, requiring immediate egress security enforcement, anomaly detection systems, and cloud firewall implementations to prevent data exfiltration.
Sources
- China-Linked Hackers Exploit Windows Shortcut Flaw to Target European Diplomatshttps://thehackernews.com/2025/10/china-linked-hackers-exploit-windows.htmlVerified
- Chinese hackers target European diplomats with Windows zero-day flawhttps://www.techradar.com/pro/security/chinese-hackers-target-european-diplomats-with-windows-zero-day-flawVerified
- Unpatched Windows vulnerability continues to be exploited by APTs (CVE-2025-9491)https://www.helpnetsecurity.com/2025/10/31/zdi-can-25373-cve-2025-9491-exploited-again/Verified
- Microsoft quietly patches LNK vulnerability that's been weaponized for yearshttps://www.techradar.com/pro/security/microsoft-quietly-patches-lnk-vulnerability-thats-been-weaponized-for-yearsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying Zero Trust Segmentation, east-west traffic controls, and strict egress policy enforcement would have limited UNC6384’s ability to escalate, move laterally, and exfiltrate sensitive data. CNSF controls focused on microsegmentation, visibility, and anomaly detection could have contained the threat and provided early warning of suspicious behavior.
Control: Threat Detection & Anomaly Response
Mitigation: Anomalous initial access attempts quickly detected and alerted for immediate response.
Control: Multicloud Visibility & Control
Mitigation: Suspicious privilege escalation patterns are detected with centralized visibility and logs.
Control: Zero Trust Segmentation
Mitigation: Lateral movement blocked by microsegmentation and least privilege policies.
Control: Inline IPS (Suricata)
Mitigation: Known malicious C2 traffic signatures detected and blocked in-line.
Control: Egress Security & Policy Enforcement
Mitigation: Unauthorized outbound data transfers identified and prevented at network egress.
Attack propagation and business disruption are contained through inline, distributed enforcement.
Impact at a Glance
Affected Business Functions
- Diplomatic Communications
- Government Operations
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive diplomatic communications and government documents.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Zero Trust Segmentation to microsegment workloads, minimizing unnecessary east-west communications.
- • Implement centralized multicloud visibility and anomaly detection for rapid identification of suspicious behaviors and privilege misuse.
- • Enforce fine-grained egress controls and FQDN filtering to detect and block unauthorized data exfiltration attempts.
- • Utilize inline IPS capability at critical cloud enforcement points to identify and block known exploit and command-and-control traffic.
- • Regularly audit cloud environments, review segmentation policies, and update detection logic in response to evolving APT tactics.



