Fire Tengu is a tracked threat actor name associated with exploitation of a Windows shortcut (.lnk) user-interface misrepresentation vulnerability identified as ZDI-CAN-25373, also tracked as ZDI-25-148. The actor is listed among intrusion sets observed abusing crafted shortcut files that conceal malicious command-line arguments from users, enabling covert payload execution through deceptive Windows shortcut behavior. This tradecraft relies on whitespace padding within shortcut command arguments so the malicious portion is not visibly rendered in the Windows properties interface, often combined with benign-looking icons and filenames to reduce user suspicion. Activity associated with exploitation of this technique has been linked broadly to state-sponsored clusters from North Korea, Iran, Russia, and China, with campaigns primarily aligned to espionage and information theft. However, the available information does not provide a high-confidence country attribution, victim-country breakdown, or sector-specific targeting profile uniquely for Fire Tengu itself. Based on the reported cluster-level activity, Fire Tengu is associated with initial access and defense-evasion tradecraft involving malicious .lnk files and hidden command execution, but additional actor-specific operational details, malware associations, and sub-group structure are not currently available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed by Trend as a threat actor associated with the broader ZDI-CAN-25373 exploitation activity.
Fire Tengu is an APT group exploiting ZDI-CAN-25373 for espionage and data theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.