Earth Akurra is a tracked threat actor name associated with exploitation of a Windows shortcut (.lnk) user-interface misrepresentation vulnerability identified as ZDI-CAN-25373, also tracked as ZDI-25-148. The actor appears in reporting alongside multiple state-sponsored intrusion sets from North Korea, Iran, Russia, and China that used crafted shortcut files to conceal malicious command-line arguments from users and facilitate payload execution. Activity linked to this cluster of actors dates back to at least 2017. The tradecraft centers on malicious .lnk files that abuse whitespace padding in command-line argument fields so Windows does not visibly display the true executed commands in the shortcut properties interface. This technique supports deceptive delivery, defense evasion, and initial compromise by making malicious shortcuts appear benign. Related campaigns using this vulnerability have primarily supported espionage and information theft objectives, with affected sectors including government, finance, telecommunications, military and defense, energy, and think tanks and NGOs across multiple world regions. High-confidence public facts in the available material establish Earth Akurra's inclusion among the actors observed exploiting this .lnk concealment technique, but do not provide sufficient corroborated detail on the group's distinct malware families, victim countries, organizational affiliation, or broader operational history beyond that exploitation set. The actor is therefore best characterized as a tracked intrusion set associated with hidden-command .lnk abuse for likely espionage-oriented operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed by Trend as a threat actor associated with the broader ZDI-CAN-25373 exploitation activity.
Earth Akurra is an APT group exploiting ZDI-CAN-25373 for espionage and data theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.