China-linked hackers target European diplomatic missions using new Windows flaw

New Delhi: A China-linked hacking group named UNC6384 has been blamed for a new cyberattack campaign targeting European diplomatic and government organisations, according to a report by cybersecurity firm Arctic Wolf.

The attacks took place between September and October 2025, exploiting an unpatched Windows shortcut (LNK) vulnerability, reported by The Hacker News.

The victims of the attack include diplomatic organizations in Hungary, Belgium, Italy, and the Netherlands, as well as government agencies in Serbia.

Arctic Wolf said the hackers used spear-phishing emails containing links that appeared related to European Commission meetings, NATO workshops, and diplomatic coordination events.

When victims clicked the links, they were led to malicious LNK files designed to exploit the Windows flaw, tracked as CVE-2025-9491 with a CVSS score of 7.0.

Once opened, these files launched a complex attack chain that ended with the deployment of PlugX malware, a dangerous remote access trojan also known by names like Destroy RAT, Korplug, and SOGU.

The malware allows hackers to control infected systems, record keystrokes, upload or download files, and gather detailed information from the compromised computers.

Researchers explained that the LNK files trigger a PowerShell command that extracts a hidden archive containing three files — a legitimate Canon printer utility, a malicious DLL file called CanonStager, and an encrypted PlugX payload.

The hackers use a technique called DLL side-loading to make the malware look like a harmless programme.

The CanonStager malware has been evolving rapidly. Arctic Wolf found that its file size had dropped from 700 KB in early September to just 4 KB by October 2025, showing that the hackers are working to make it smaller, stealthier, and harder to detect.

In some cases, the attackers also used HTML Application (HTA) files that loaded external JavaScript from cloudfront[.]net domains to deliver the malware.

This shows that UNC6384 continues to refine its methods to stay ahead of security defences.

Cybersecurity researchers have also linked UNC6384 to another China-based hacking group known as Mustang Panda, known for targeting government and diplomatic entities across Europe and Asia.

The group has been seen deploying memory-resident versions of PlugX, referred to as SOGU.SEC.

Experts say the campaign aligns with China’s intelligence-gathering goals, particularly to monitor European defense cooperation, policy coordination, and alliance strength.

Microsoft has confirmed that its Defender antivirus can detect and block this type of attack, while Smart App Control adds another protection layer by blocking malicious files downloaded from the internet.

According to Arctic Wolf, the continued targeting of European diplomatic entities highlights China’s growing cyber espionage focus on understanding the inner workings of European alliances and defence strategies.

IANS

 

India’s indigenous GSAT-7R satellite to bolster Navy’s communications successfully separated

Sriharikota (Andhra Pradesh):The Indian Space Research Organisation (ISRO) on Sunday successfully achieved the separation and injection of the Indian Navy’s GSAT-7R (CMS-03) communication satellite, which would strengthen the force's space-based...

IIT Kanpur Director explains why cloud seeding didn’t cause rain in Delhi; another attempt planned today

New Delhi: The much-anticipated attempt to induce artificial rain through cloud seeding over parts of Delhi turned out to be “not completely successful.” According to IIT Kanpur Director Manindra Agrawal,...

Covid mRNA vaccine may be used to fight lung, skin cancer

  New Delhi:  The breakthrough mRNA vaccine that enabled the world to fight Covid-19 may also be used to fight cancers of the lung or skin, according to a study....

US, Japanese scientists awarded 2025 Nobel Prize for Medicine for discovery on immune system

New Delhi: A trio of US and Japanese scientists have on Monday been awarded the 2025 Nobel Prize in Physiology or Medicine for their discovery on how the immune system...

Global Dialogue on AI Governance launched at United Nations

United Nations: The Global Dialogue on Artificial Intelligence (AI) Governance was launched at the United Nations. "The question is no longer whether AI will transform our world -- it already...

Samsung to bring Galaxy AI to over 400 million devices by 2025 end, to hire 60,000 in 5 years

New Delhi/Seoul: Samsung has said it aims to bring the Galaxy AI experience to over 400 million devices worldwide by the end of this year. Samsung launched the world’s first...

First telecom system with India-made chips gets TEC certification

New Delhi: Union Electronics and IT Minister Ashwini Vaishnaw has announced that a telecom system using only domestically-produced chips has received certification from the Telecommunication Engineering Centre (TEC). The minister...

‘No fear, just beauty’: Astronomer calls Sept 7 lunar eclipse a rare celestial spectacle

New Delhi: The upcoming lunar eclipse on Sunday (September 7) will be a rare astronomical alignment, a leading astronomer said. The eclipse, visible across most parts of India, will be...

India’s smallest chip will bring biggest change to world: PM Modi

New Delhi: Prime Minister Narendra Modi on Tuesday said that the day is not far when India’s smallest chip will bring the biggest change in the world. Inaugurating ‘Semicon India...

India gets first fully indigenous 32-bit chip ‘Vikram’ built by ISRO lab

New Delhi: In a significant feat for the country to become a global semiconductor hub, Union Minister for Electronics and IT Ashwini Vaishnaw on Tuesday presented the first made-in-India processor,...

Gaganyaan’s 1st uncrewed mission ready to launch with half-humanoid robot in Dec: ISRO

New Delhi: The first uncrewed mission of the Gaganyaan human spaceflight mission, G1, is ready to launch with the half-humanoid robot -- Vyommitra -- and the launch is expected in...

Space mission achieved all technical objectives, results encouraging: Shubhanshu Shukla

New Delhi: IAF Group Captain Shubhanshu Shukla on Thursday said that his mission to the International Space Station (ISS) -- a first ever by an Indian -- has achieved all...

Read Previous

India’s indigenous GSAT-7R satellite to bolster Navy’s communications successfully separated

Read Next

9 critical after 10 stabbed in train in UK’s Cambridgeshire, 2 suspects arrested

WP2Social Auto Publish Powered By : XYZScripts.com