Earth Iktomi is a tracked threat actor observed exploiting the Windows shortcut vulnerability ZDI-CAN-25373 through specially crafted LNK files. The actor has been identified in targeted attack activity in which malicious shortcut files are used to conceal command-line execution from users by abusing whitespace padding and deceptive shortcut presentation. Observed execution chains associated with this technique include launching command interpreters and scripting utilities from LNK files, enabling covert payload delivery and follow-on compromise. Earth Iktomi has been associated with activity consistent with advanced persistent threat operations rather than commodity opportunistic abuse. Campaigns involving this exploitation pattern have been linked broadly to espionage and information theft objectives, and the actor appears among intrusion sets leveraging the technique against organizations in sectors such as government, finance, telecommunications, military and defense, energy, and think tanks or NGOs. Victimology tied to this exploitation cluster spans multiple regions worldwide, including North America, Europe, Asia, South America, Africa, and Australia. The actor’s known tradecraft in the available reporting centers on initial access and execution via malicious LNK files, use of spoofed or misleading shortcut presentation to reduce user suspicion, and hidden command execution for payload staging. High-confidence public details beyond this exploitation pattern, including definitive national attribution, additional aliases, or a broader malware/tooling profile, are not currently available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed by Trend as a threat actor associated with the broader ZDI-CAN-25373 exploitation activity.
Observed leveraging the Windows shortcut zero-day vulnerability ZDI-CAN-25373 in targeted attacks using specially crafted LNK files to execute malicious code.
Earth Iktomi is an APT group exploiting ZDI-CAN-25373 for espionage and data theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.