Chinese hackers target European diplomats with Windows zero-day flaw


  • Mustang Panda used CVE-2025-9491 to target European diplomats via phishing and malicious .LNK files
  • Exploited Windows Shell Link flaw deploys PlugX RAT for persistent access and data exfiltration
  • Hundreds of samples link Zero Day to long-running Chinese espionage campaigns since at least 2017

Chinese state-sponsored threat actors have abused a Windows zero-day vulnerability to target diplomats across the European continent, security researchers warn.

Security researchers Arctic Wolf Labs recently said they observed a nation-state actor known as Mustang Panda (UNC6384) sending spear-phishing emails to diplomats in Hungary, Belgium, Serbia, Italy and the Netherlands.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top