Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

Why that harmless looking desktop icon might actually be a weapon

Hackers exploit the fact that Windows only displays the first 255 characters of a shortcut target path.

byKerem Gülen
November 24, 2025
in Cybersecurity, News
Home News Cybersecurity
Share on FacebookShare on TwitterShare on LinkedInShare on WhatsAppShare on e-mail
Google Preferred Source

A long-standing vulnerability in Windows shortcut files (LNK) is being actively exploited by state-sponsored hacking groups to launch cyberattacks against government entities and diplomats, according to new security reports. The flaw, tracked as CVE-2025-9491, allows attackers to hide malicious code within the seemingly harmless shortcut icons used daily by millions of users.

Despite the growing number of attacks, Microsoft has reportedly decided not to release a direct patch for the issue, citing the risk of breaking legitimate operating system functionality.

Windows LNK files are typically used to point to applications or documents. However, they can also be configured to execute system commands. The vulnerability lies in how Windows displays these file properties to the user.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

While the Windows user interface only displays the first 255 characters of a shortcut’s target path, the file format itself supports up to 4,096 characters. Attackers exploit this gap by “padding” their malicious commands with extensive whitespace. When a user inspects the file properties, they see a benign path, but the hidden malicious arguments—such as PowerShell scripts that download malware—execute immediately upon opening the file.

Security researchers have linked this technique to high-profile espionage campaigns. One group, tracked as XDSpy, has targeted government agencies in Eastern Europe. In these attacks, the group utilized LNK files to trigger a legitimate, Microsoft-signed executable. This executable then sideloaded a malicious DLL file to install the “XDigo” payload, which is capable of stealing sensitive data, capturing screenshots, and logging keystrokes.

Another threat actor, identified as UNC6384, has been observed targeting European diplomats. This group uses similar whitespace-padding tactics to hide PowerShell commands that deploy the PlugX remote-access trojan, a tool commonly associated with Chinese cyber-espionage operations. Reports indicate these attacks have been used to compromise systems in Hungary, Belgium, and other NATO-aligned nations.

According to reports from Help Net Security, Microsoft has determined that this specific vulnerability “did not meet the bar for servicing.” The company’s stance is that the ability for shortcuts to launch programs with arguments is a fundamental feature of the Windows operating system, and altering this behavior could disrupt legitimate software.

Instead of a code fix, Microsoft is relying on its security ecosystem to mitigate the threat. The company states that Microsoft Defender is capable of flagging malicious shortcuts, and its Smart App Control feature can block untrusted files downloaded from the internet.

Security experts advise users to treat LNK files with the same caution reserved for executable (.EXE) files, especially when they arrive via email or inside ZIP archives. Because the Windows interface may not reveal the full danger of a file, visual inspection is no longer a reliable safety measure.

For enterprise environments, security teams are recommended to configure policies such as AppLocker to restrict shortcut files from launching command-line tools like PowerShell. For individual users, keeping antivirus software up-to-date remains the primary line of defense against these “zero-click” or single-click execution attacks.


Featured image credit

Tags: windows 11

Related Posts

X releases redesigned Android app with faster performance

X releases redesigned Android app with faster performance

July 21, 2026
Google reportedly develops Frozen v2 chip for Gemini AI

Google reportedly develops Frozen v2 chip for Gemini AI

July 21, 2026
Samsung Galaxy Watch Ultra 2 renders leak

Samsung Galaxy Watch Ultra 2 renders leak

July 21, 2026
NVIDIA unveils hot-water cooled AI servers

NVIDIA unveils hot-water cooled AI servers

July 21, 2026
Amazon rolls out Adaptive Display for Fire TV

Amazon rolls out Adaptive Display for Fire TV

July 21, 2026
Moonshot pauses Kimi K3 signups amid GPU shortage

Moonshot pauses Kimi K3 signups amid GPU shortage

July 20, 2026

LATEST NEWS

X releases redesigned Android app with faster performance

Google reportedly develops Frozen v2 chip for Gemini AI

Samsung Galaxy Watch Ultra 2 renders leak

NVIDIA unveils hot-water cooled AI servers

Amazon rolls out Adaptive Display for Fire TV

Moonshot pauses Kimi K3 signups amid GPU shortage

BEST AI MODELS LEADERBOARD

See the best AI models, ranked by intelligence, benchmark results, speed and token price. Find the most suitable LLMs, Text-to-Image, Image Editing, Text-to-Speech, Text-to-Video and Image-to-Video  artificial intelligence model for your tasks and business.

LATEST TOOLS

Amanda AI

InterviewBot

VernAI

MyLoans

Essay Grader AI

Cover Letter AI

Animate Old Photos

Resume.io

MonAI

AIEngine Plugin

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI tools
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies to improve your experience. You can choose to accept or reject them. Visit our Privacy Policy.