EXECUTIVE SUMMARY:
Researchers have uncovered a cyber-espionage campaign attributed to the threat actor known as XDSpy. This campaign primarily targets governmental entities in Eastern Europe and Russia, utilizing a multi-stage infection chain to deploy the XDigo malware. The operation leverages a previously unreported vulnerability in Microsoft Windows LNK (shortcut) files, identified as ZDI-CAN-25373, which has been exploited by multiple state-sponsored groups.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Researchers have uncovered a cyber-espionage campaign attributed to the threat actor known as XDSpy. This campaign primarily targets governmental entities in Eastern Europe and Russia, utilizing a multi-stage infection chain to deploy the XDigo malware. The operation leverages a previously unreported vulnerability in Microsoft Windows LNK (shortcut) files, identified as ZDI-CAN-25373, which has been exploited by multiple state-sponsored groups.[emaillocker id="1283"]
The exploitation of the ZDI-CAN-25373 vulnerability involves crafting LNK files that conceal command-line arguments within Windows Explorer UI. By inserting enough whitespace characters before the executable path and command arguments, attackers can hide the execution details from the user interface, thereby facilitating the stealthy execution of malicious payloads. This technique is employed in the initial stage of the infection chain, where LNK files are used to download and execute the XDigo malware. XDigo, a Go-based implant, serves as the primary payload, establishing a foothold on the compromised systems. Further analysis reveals that XDSpy has maintained consistent infrastructure across various campaigns, indicating a persistent and evolving threat actor.
The discovery of the XDSpy campaign underscores the increasing sophistication of cyber-espionage tactics, particularly the abuse of legitimate system features such as the exploitation of Windows LNK files through the vulnerability ZDI-CAN-25373 to evade detection. Organizations, especially those within the targeted regions, should prioritize the implementation of robust security measures, including the deployment of endpoint detection and response (EDR) solutions, regular patching of known vulnerabilities, and user education to recognize suspicious activities. Given the persistent nature of XDSpy's operations, continuous monitoring and proactive threat intelligence sharing are essential to mitigate potential risks.
THREAT PROFILE:
| Tactic | Technique Id | Technique | Sub-technique |
| Initial Access | T1566.001 | Phishing | Spearphishing Attachment |
| Execution | T1204.002 | User Execution | Malicious File |
| T1059 | Command and Scripting Interpreter | PowerShell | |
| T1059.003 | Windows Command Shell | ||
| T1203 | Exploitation for Client Execution | — | |
| Defense Evasion | T1218.011 | Signed Binary Proxy Execution | Rundll32 |
| T1140 | Deobfuscate/Decode Files or Information | — | |
| Discovery | T1082 | System Information Discovery | — |
| T1057 | Process Discovery | — | |
| Command and Control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | — |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]