Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
state-sponsored-espionagegovernment-diplomatic-threatphishing-campaign-intelligenceremote-access-implant

UNC6384 Espionage Campaign Exploits Windows Shortcut Vulnerability Against European Diplomats

Updated 3mo agoFirst seen Oct 30, 202515 sources

Chinese state-sponsored threat actor UNC6384 conducted a targeted cyber-espionage campaign against European diplomatic entities in Hungary, Belgium, Italy, the Netherlands, and Serbia during September and October 2025. The attackers exploited an unpatched Windows shortcut vulnerability (ZDI-CAN-25373), first disclosed in March 2025, to deliver the PlugX remote access trojan via spearphishing emails themed around European Commission meetings, NATO workshops, and multilateral diplomatic events. The campaign leveraged advanced social engineering, detailed knowledge of diplomatic calendars, and multi-stage malware delivery chains, including DLL side-loading through legitimate Canon printer utilities. Arctic Wolf Labs and other researchers attributed the activity to UNC6384, noting the group’s rapid adoption of public vulnerabilities and operational expansion from Southeast Asia to Europe.

The campaign’s objectives included stealing sensitive defense and national security information, monitoring NATO and EU policy development, and assessing European military readiness and supply chain resilience. The attacks began with highly targeted phishing lures, leading to the exploitation of ZDI-CAN-25373 and subsequent deployment of PlugX, which enabled remote access, data theft, and further malware installation. The campaign highlights the ongoing risk posed by unpatched vulnerabilities and the increasing sophistication of Chinese cyber-espionage operations targeting Western diplomatic and governmental organizations.

Share:
UNC6384 Espionage Campaign Exploits Windows Shortcut Vulnerability Against European Diplomats
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Oct 31, 20258mo ago

Reports highlight continued exploitation of unpatched CVE-2025-9491

By October 31, 2025, multiple outlets emphasized that the Windows shortcut flaw remained unpatched and was being actively exploited by UNC6384 and other state-sponsored actors. Coverage noted Microsoft's decision not to issue a fix and the need for mitigations such as blocking untrusted .LNK files and monitoring for related indicators.

Follow-on reporting expands known victim scope across Europe

From October 30 to October 31, 2025, follow-on coverage highlighted additional affected organizations and countries, including diplomatic targets in Italy and the Netherlands and government agencies in Serbia. The reporting reinforced that the campaign likely extended beyond the initially disclosed Hungarian and Belgian entities.

Oct 30, 20258mo ago

Arctic Wolf attributes the campaign to UNC6384 and publishes findings

On October 30, 2025, Arctic Wolf Labs published research attributing the active espionage campaign with high confidence to the Chinese-affiliated threat actor UNC6384. The report detailed targeting of diplomatic entities in Hungary and Belgium and assessed the activity as aligned with PRC intelligence interests in Europe.

Oct 1, 20259mo ago

Attackers refine delivery tradecraft and shrink CanonStager artifacts

By October 2025, Arctic Wolf observed rapid evolution in the campaign's tooling, including CanonStager shrinking to roughly 4 KB. Researchers also noted alternative delivery paths, including HTA/JavaScript payload retrieval via a CloudFront-based infrastructure.

Sep 1, 202510mo ago

UNC6384 exploits the LNK flaw to deploy PlugX on victim systems

In the September–October 2025 campaign, malicious Windows shortcut files exploited ZDI-CAN-25373/CVE-2025-9491 to trigger obfuscated PowerShell and deliver PlugX. The infection chain used a legitimate Canon utility, a malicious sideloaded DLL dubbed CanonStager, and an encrypted payload executed in memory.

UNC6384 launches spearphishing campaign against European diplomatic targets

During September 2025, UNC6384 began targeting European diplomatic and government entities with spearphishing lures themed around real diplomatic events. Initial victimology included organizations in Hungary and Belgium, with broader targeting later linked to Serbia, Italy, and the Netherlands.

Mar 1, 20251y ago

ZDI publicly discloses Windows shortcut flaw ZDI-CAN-25373

In March 2025, the Windows shortcut vulnerability tracked as ZDI-CAN-25373 was publicly disclosed. Later reporting tied the issue to CVE-2025-9491 and noted it could enable hidden command execution via manipulated .LNK files.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

23 LINKEDOpen in app
Threat actors
2 linked
Malware
3 linked
Affected products
3 linked
WindowsAmazon CloudfrontPowershell
Organizations
14 linked
Arctic WolfCanonTrend MicroMicrosoft CorporationBroadcomGoogleUNC6384Mustang PandaEsetHarfangLabStrikeReadyenisaEuropean CommissionUniversity of North Carolina
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

UNC6384 Espionage Campaign Exploits Windows Shortcut Vulnerability Against European Diplomats | Mallory