Water Glashtyn is a tracked threat cluster observed exploiting the Windows shortcut vulnerability ZDI-CAN-25373 through specially crafted LNK files. The cluster has been identified in targeted attack activity alongside other advanced persistent threat groups using padded shortcut content to conceal malicious command-line arguments from users and trigger execution of commands through Windows utilities such as command interpreters and PowerShell. Observed delivery vectors for these malicious shortcut files include network-accessible mechanisms such as HTTP and SMB. Water Glashtyn has been associated with campaigns leveraging deceptive shortcut presentation and hidden execution behavior consistent with espionage-oriented intrusion tradecraft. High-confidence public reporting directly ties the cluster to exploitation of this LNK-based zero-day technique, but does not provide sufficient corroborated detail in the supplied facts to attribute a country of origin, define a broader malware portfolio, or enumerate a fuller victimology specific to this actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed by Trend as a threat actor associated with the broader ZDI-CAN-25373 exploitation activity.
Observed leveraging the Windows shortcut zero-day vulnerability ZDI-CAN-25373 in targeted attacks using specially crafted LNK files to execute malicious code.
Water Glashtyn is one of several APT groups attributed to exploiting ZDI-CAN-25373 for espionage and data theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.