Water Poukai is a tracked threat actor observed exploiting the Windows shortcut vulnerability ZDI-CAN-25373 through specially crafted .lnk files. The actor has been identified among multiple advanced persistent threat groups using this technique in targeted intrusion activity. The tradecraft associated with Water Poukai includes delivery of malicious shortcut files that conceal command-line arguments from users through whitespace padding and deceptive presentation, enabling execution of commands via native Windows interpreters and utilities such as command shells and PowerShell. This reflects a focus on initial access, defense evasion, and post-exploitation execution through disguised shortcut-based lures. Water Poukai has been associated with broader campaigns in which exploitation of this vulnerability supported espionage and data-theft objectives. Publicly available facts in this context do not provide a corroborated country attribution, alias set beyond the same name, or a more detailed victimology specific to this actor alone.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed by Trend as a threat actor associated with the broader ZDI-CAN-25373 exploitation activity.
Observed leveraging the Windows shortcut zero-day vulnerability ZDI-CAN-25373 in targeted attacks using specially crafted LNK files to execute malicious code.
Water Poukai is an APT group exploiting ZDI-CAN-25373 for espionage and data theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.