UNC6384 Weaponizes ZDI-CAN-25373 Vulnerability to Deploy PlugX Against Hungarian and Belgian Diplomatic Entities
Oct. 31, 2025, 9:45 a.m.
Description
Chinese-affiliated threat actor UNC6384 is conducting a cyber espionage campaign targeting European diplomatic entities, particularly in Hungary and Belgium. The group exploits the ZDI-CAN-25373 Windows vulnerability to deliver PlugX malware through spearphishing emails with malicious LNK files. The campaign uses diplomatic conference themes as lures and employs DLL side-loading of legitimate Canon printer utilities. UNC6384 has expanded its operations from Southeast Asia to Europe, demonstrating rapid adoption of new vulnerabilities and refined social engineering techniques. The malware provides persistent remote access for intelligence collection on European foreign policy, defense cooperation, and economic matters. This campaign highlights the evolving capabilities of Chinese cyber espionage efforts and their strategic focus on diplomatic targets.
Tags
Date
- Created: Oct. 31, 2025, 8:35 a.m.
- Published: Oct. 31, 2025, 8:35 a.m.
- Modified: Oct. 31, 2025, 9:45 a.m.
Indicators
- f04340f93e2f5f7d6d5521572f17c5b80f39984ee6b4b8c0899380e95a825127
- f8d03814986599ed98ce8c83fbc9ce55b83095c179c54ec555c4ab372fa99700
- ee9295fa36e29808ff36beb55be328b68d82f267d2faa54db26e0bf86b78fa56
- d70600f0e4367e6e3e07f7b965b654e5bfbcb0afbccfe0f6a9a8d9f69c7061a3
- e53bc08e60af1a1672a18b242f714486ead62164dda66f32c64ddc11ffe3f0df
- c96338533d0ab4de8201ce1f793e9ea18d30c6179daf1e312e0f01aff8f50415
- c9128d72de407eede1dd741772b5edfd437e006a161eecfffdf27b2483b33fc7
- c3b7abcb583b90559af973dd18bf5ccba48d3323e5e2e8bc0b11ff54425e34dd
- bb491248bb8f6067af39e196b11f4e408a7a3885704cadbd4266db52ae4b03e2
- ae8d2cef8eac099f892e37cc50825d329459baa9625b71fb6f4b7e8f33c6ccce
- a7d12712673a4e3b6d62a9d84f124e62689da12f0a3ee6009369ecf469ce8182
- 911cccd238fbfdb4babafc8d2582e80dcfa76469fa1ee27bbc5f4324d5fca539
- 7a49310a9192cab1aa05256b6ca0d0c1a54fe084b103ff4df2d17be9effa3300
- 7168838787039d82961836e5f2f9c70f3fe7c4d99a6c7c61405b3364ce37e760
- 716637a424bce58ff8c75e40b6e29c33318ff185af6e9e62d85b61e56a560eac
- 3fe6443d464f170f13d7f484f37ca4bcae120d1007d13ed491f15427d9a7121f
- 274adf7f60e0799b157e7524d503d345f6870010703fb6b56a3dd1e62b4de3e8
- 218ed813d8a4d9d05473338795021c66012cd6c36368561d3aaf831a5c494740
- 262a1003a2cd04993b29e687686eba573d6202fea8611c437ecbd6312802677a
- 1564e19b36ffc4e12becc4fb73359de13191ac8df62def45f045efbd6ef36e79
- 4ed76fa68ef9e1a7705a849d47b3d9dcdf969e332bd5bcb68138579c288a16d3
- racineupci.org
- paquimetro.net
- naturadeco.net
- dorareco.net
- cseconline.org
Additional Informations
- Government
- Hungary
- Belgium
- Serbia
- Netherlands
- Italy