Water Cetus is a tracked intrusion set associated with exploitation of a Windows shortcut (.lnk) user-interface misrepresentation technique that conceals malicious command-line arguments from users. It has been identified among a broader cluster of state-sponsored groups observed abusing crafted .lnk files to hide execution behavior and facilitate malicious payload delivery. This tradecraft supports stealthy initial access and execution by making shortcut files appear benign while masking the commands they launch. The actor’s observed activity is consistent with espionage-oriented operations and information theft. Campaigns linked to this .lnk abuse have targeted organizations across government, finance, telecommunications, military and defense, energy, and think tanks and NGOs on multiple continents. The technique relies on whitespace padding within shortcut metadata so that Windows does not visibly render the full malicious command in the shortcut properties interface, often combined with deceptive icons and filenames to increase plausibility. Water Cetus is one of several named intrusion sets tracked in connection with this activity alongside groups such as Water Glashtyn, Water Poukai, Water Asena, Earth Iktomi, Earth Balayang, Fire Tengu, Earth Imp, Earth Akurra, Earth Anansi, Earth Gelert, Earth Vetala, Earth Kapre, Earth Preta, Earth Tengshe, and Earth Lusca. Publicly available facts in this context do not provide high-confidence attribution of Water Cetus to a specific country, nor do they establish distinct malware families, sub-groups, or victim countries uniquely attributable to this actor beyond its inclusion in the broader exploitation cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed by Trend as a threat actor associated with the broader ZDI-CAN-25373 exploitation activity.
Water Cetus is an APT group exploiting ZDI-CAN-25373 for espionage and data theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.