logo

[demo] CVE 2025 9491 Briefing

ID: d81ca992-2b07-469b-ad9a-4284f653aa3f

STIX ID: report--d81ca992-2b07-469b-ad9a-4284f653aa3f

Threat Score

100/100

Uploaded: 2025-11-14

Created by: dogesec demos

TLP:CLEAR
...
...
This report covers CVE-2025-9491, a Windows .LNK UI misrepresentation vulnerability enabling remote code execution that is being actively exploited by UNC6384 in spear-phishing campaigns against European diplomatic and aviation targets. The attack chain uses malicious .LNK files to launch disguised payloads and deploy PlugX via DLL sideloading with legitimate Canon utilities, with associated ATT&CK techniques, IOCs (email themes, delivery mechanisms, LNK traits, network patterns), and recommended preventive, detection, and response controls to mitigate risk.