CINXE.COM
CVE-2025-0411: Ukrainian Organizations Targeted in Zero-Day Campaign and Homoglyph Attacks | Trend Micro (HK)
<!DOCTYPE HTML> <html lang="en-HK"> <!-- OneTrust Cookies Consent Notice start for trendmicro.com --> <script type="text/javascript" src="https://cdn.cookielaw.org/consent/821060e3-3f9c-4a2f-8613-8e0db4841f79/OtAutoBlock.js"></script> <script src="https://cdn.cookielaw.org/scripttemplates/otSDKStub.js" type="text/javascript" charset="UTF-8" data-domain-script="821060e3-3f9c-4a2f-8613-8e0db4841f79"></script> <script type="text/javascript">function OptanonWrapper() { }</script> <!-- OneTrust Cookies Consent Notice end for trendmicro.com --> <script type="text/javascript" src="/etc.clientlibs/clientlibs/granite/jquery.min.js"></script> <script type="text/javascript" src="/etc.clientlibs/clientlibs/granite/utils.min.js"></script> <script type="text/javascript"> if (typeof Granite !== "undefined" && Granite.I18n){ Granite.I18n.setLocale("en_hk" || "en"); } </script> <head> <meta charset="UTF-8"/> <meta name="viewport" content="width=device-width, initial-scale=1"/> <meta name="description" content="The ZDI team offers an analysis of how CVE-2025-0411, a zero-day vulnerability in 7-Zip was actively exploited to target Ukrainian organizations through spear-phishing and homoglyph attacks."/> <meta name="robots" content="index,follow"/> <meta name="keywords" content="apt & targeted attacks,endpoints,exploits & vulnerabilities,research,articles, news, reports"/> <meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1"/> <meta name="template" content="article1withouthero"/> <meta property="article:published_time" content="2025-02-04"/> <meta property="article:tag" content="exploits & vulnerabilities"/> <meta property="article:section" content="research"/> <link rel="icon" type="image/ico" href="/content/dam/trendmicro/favicon.ico"/> <link rel="canonical" href="https://www.trendmicro.com/en_hk/research/25/a/cve-2025-0411-ukrainian-organizations-targeted.html"/> <title>CVE-2025-0411: Ukrainian Organizations Targeted in Zero-Day Campaign and Homoglyph Attacks | Trend Micro (HK)</title> <link href="https://fonts.googleapis.com/css?family=Open+Sans:300,300i,400,400i,600" rel="stylesheet"/> <link href="//customer.cludo.com/css/296/1798/cludo-search.min.css" type="text/css" rel="stylesheet"/> <link rel="stylesheet" href="/etc.clientlibs/trendresearch/clientlibs/clientlib-trendresearch.min.css" type="text/css"> <link rel="stylesheet" href="/etc.clientlibs/trendmicro/clientlibs/trendmicro-core-2/clientlibs/header-footer.min.css" type="text/css"> <script src="//tags.tiqcdn.com/utag/trendmicro/apaccms/prod/utag.sync.js"></script> <meta property="og:url" content="https://www.trendmicro.com/en_hk/research/25/a/cve-2025-0411-ukrainian-organizations-targeted.html"/> <meta property="og:title" content="CVE-2025-0411: Ukrainian Organizations Targeted in Zero-Day Campaign and Homoglyph Attacks"/> <meta property="og:description" content="The ZDI team offers an analysis of how CVE-2025-0411, a zero-day vulnerability in 7-Zip was actively exploited to target Ukrainian organizations through spear-phishing and homoglyph attacks."/> <meta property="og:site_name" content="Trend Micro"/> <meta property="og:image" content="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/thumbnails/25/cve-2025-0411-cover.png"/> <meta property="og:locale" content="en_HK"/> <meta name="twitter:card" content="summary_large_image"/> <meta name="twitter:site" content="@TrendMicro"/> <meta name="twitter:title" content="CVE-2025-0411: Ukrainian Organizations Targeted in Zero-Day Campaign and Homoglyph Attacks"/> <meta name="twitter:description" content="The ZDI team offers an analysis of how CVE-2025-0411, a zero-day vulnerability in 7-Zip was actively exploited to target Ukrainian organizations through spear-phishing and homoglyph attacks."/> <meta name="twitter:image" content="https://www.trendmicro.com/content/dam/trendmicro/global/en/research/thumbnails/25/cve-2025-0411-cover.png"/> </head> <body class="articlepage page basicpage context-business"> <!-- Page Scroll: Back to Top --> <a id="page-scroll" title="VerticalPageScroll" href="javascript:jumpScroll($(this).scrollTop());"> <span class="icon-chevron-up"></span> </a> <!-- /* Data Layers */ --> <script type="text/javascript"> var utag_data = {"customer_cookie_type":"business","language_code":"en_hk","page_name":"research/25/a/cve-2025-0411-ukrainian-organizations-targeted/en_hk","category_id":"en_hk/research/25/a/cve-2025-0411-ukrainian-organizations-targeted","page_type":"unknown","site_section":"research","post_author":"Peter Girnus|Sr. Threat Researcher","post_date":"2025-02-04"}; </script> <script type="text/javascript"> window.adobeDigitalData = typeof(window.adobeDigitalData) != "undefined" ? window.adobeDigitalData : []; window.adobeDigitalData.push( {"pageID":"a2098a56da99","articleTitle":"CVE-2025-0411: Ukrainian Organizations Targeted in Zero-Day Campaign and Homoglyph Attacks","description":"The ZDI team offers an analysis of how CVE-2025-0411, a zero-day vulnerability in 7-Zip was actively exploited to target Ukrainian organizations through spear-phishing and homoglyph attacks.","thumbnailUrl":"/content/dam/trendmicro/global/en/research/thumbnails/25/cve-2025-0411-cover.png","pageUrl":"https://www.trendmicro.com/en_hk/research/25/a/cve-2025-0411-ukrainian-organizations-targeted.html","publishedDate":"2025-02-04","pageTag":"exploits & vulnerabilities","pageSection":"research","pageMedium":"articles, news, reports"} ); </script> <script type="text/javascript">(function(a,b,c,d){a='//tags.tiqcdn.com/utag/trendmicro/apaccms/prod/utag.js';b=document;c='script';d=b.createElement(c);d.src=a;d.type='text/java'+c;d.async=true;a=b.getElementsByTagName(c)[0];a.parentNode.insertBefore(d,a);})();</script> <div class="businessHeaderV1"> <div class="headerAssemblyV1"> <header class="page-header"> <nav> <div class="header-bar"> <div class="logo"> <a id="header-logo" href="/en_hk/business.html"> <img src="/content/dam/trendmicro/global/en/core/images/logos/tm-logo-red-white-t.svg"/> <p>Business</p> </a> </div> <div class="inner-nav-wrapper"> <span class="material-symbols-outlined search-icon">search</span> <span class="material-symbols-outlined close-search-icon">close</span> <input type="checkbox" id="checkbox" class="hamburger-menu"/> <div aria-label="Menu" class="hamburger"></div> </div> </div> <div class="hamburger-wrapper"> <div class="mainNavMenuV1"><div class="mainNavMenu mainNavMenuV1"> <div class="list-wrapper inital-list-wrapper"> <ul class="menu nav-level-0"> <li> <!-- Level 0, top menu --> <div class="label">Solutions</div> <ul class="sub-menu nav-level-1"> <li> <div class="label branch"> <a class="menu-link" href="/en_hk/business/solutions/challenges.html">By Challenge</a> </div> <ul class="branch nav-item-2"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/solutions/challenges.html">By Challenge</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">By Challenge</div> <a class="leaf-button color-d71920" href="/en_hk/business/solutions/challenges.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/solutions/challenges/cyber-risk.html">Understand, Prioritize & Mitigate Risks</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Understand, Prioritize & Mitigate Risks</div> <p class="copy">Improve your risk posture with attack surface management</p> <a class="leaf-button color-d71920" href="/en_hk/business/solutions/challenges/cyber-risk.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/solutions/challenges/cloud-native-applications.html">Protect Cloud-Native Apps</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Protect Cloud-Native Apps</div> <p class="copy">Security that enables business outcomes</p> <a class="leaf-button color-d71920" href="/en_hk/business/solutions/challenges/cloud-native-applications.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/solutions/challenges/hybrid-cloud.html">Protect Your Hybrid World</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Protect Your Hybrid, Multi-Cloud World</div> <p class="copy">Gain visibility and meet business needs with security</p> <a class="leaf-button color-d71920" href="/en_hk/business/solutions/challenges/hybrid-cloud.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/solutions/challenges/infrastructure-security.html">Securing Your Borderless Workforce</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Securing Your Borderless Workforce</div> <p class="copy">Connect with confidence from anywhere, on any device</p> <a class="leaf-button color-d71920" href="/en_hk/business/solutions/challenges/infrastructure-security.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/solutions/challenges/network-security.html">Eliminate Network Blind Spots</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Eliminate Network Blind Spots</div> <p class="copy">Secure users and key operations throughout your environment</p> <a class="leaf-button color-d71920" href="/en_hk/business/solutions/challenges/network-security.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/solutions/challenges/detection-response.html">See More. Respond Faster.</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">See More. Respond Faster.</div> <p class="copy">Move faster than your adversaries with powerful purpose-built XDR, attack surface risk management, and zero trust capabilities</p> <a class="leaf-button color-d71920" href="/en_hk/business/solutions/challenges/detection-response.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/solutions/challenges/managed-services.html">Extend Your Team</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Extend Your Team. Respond to Threats Agilely</div> <p class="copy">Maximize effectiveness with proactive risk reduction and managed services</p> <a class="leaf-button color-d71920" href="/en_hk/business/solutions/challenges/managed-services.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/solutions/challenges/zero-trust.html">Operationalizing Zero Trust</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Operationalizing Zero Trust</div> <p class="copy">Understand your attack surface, assess your risk in real time, and adjust policies across network, workloads, and devices from a single console</p> <a class="leaf-button color-d71920" href="/en_hk/business/solutions/challenges/zero-trust.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> </ul> </li> <li> <div class="label branch"> <a class="menu-link" href="/en_hk/business/solutions/role.html">By Role</a> </div> <ul class="branch nav-item-2"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/solutions/role.html">By Role</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">By Role</div> <a class="leaf-button color-d71920" href="/en_hk/business/solutions/role.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/solutions/role/ciso.html">CISO</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">CISO</div> <p class="copy">Drive business value with measurable cybersecurity outcomes</p> <a class="leaf-button color-d71920" href="/en_hk/business/solutions/role/ciso.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/solutions/role/soc.html">SOC Manager</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">SOC Manager</div> <p class="copy">See more, act faster</p> <a class="leaf-button color-d71920" href="/en_hk/business/solutions/role/soc.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/solutions/role/it-infrastructure-operations.html">Infrastructure Manager</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Infrastructure Manager</div> <p class="copy">Evolve your security to mitigate threats quickly and effectively</p> <a class="leaf-button color-d71920" href="/en_hk/business/solutions/role/it-infrastructure-operations.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/solutions/role/cloud-developer.html">Cloud Builder and Developer</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Cloud Builder and Developer</div> <p class="copy">Ensure code runs only as intended</p> <a class="leaf-button color-d71920" href="/en_hk/business/solutions/role/cloud-developer.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/solutions/role/cloud-operations.html">Cloud Security Ops</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Cloud Security Ops</div> <p class="copy">Gain visibility and control with security designed for cloud environments</p> <a class="leaf-button color-d71920" href="/en_hk/business/solutions/role/cloud-operations.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> </ul> </li> <li> <div class="label branch"> <a class="menu-link" href="/en_hk/business/capabilities/solutions-for.html">By Industry</a> </div> <ul class="branch nav-item-2"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/capabilities/solutions-for.html">By Industry</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">By Industry</div> <a class="leaf-button color-d71920" href="/en_hk/business/capabilities/solutions-for.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/capabilities/solutions-for/healthcare.html">Healthcare</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Healthcare</div> <p class="copy">Protect patient data, devices, and networks while meeting regulations</p> <a class="leaf-button color-d71920" href="/en_hk/business/capabilities/solutions-for/healthcare.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/solutions/iot/ics-ot.html">Manufacturing</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Manufacturing</div> <p class="copy">Protecting your factory environments – from traditional devices to state-of-the-art infrastructures</p> <a class="leaf-button color-d71920" href="/en_hk/business/solutions/iot/ics-ot.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/solutions/iot/ics-ot.html">Oil & Gas</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Oil & Gas</div> <p class="copy">ICS/OT Security for the oil and gas utility industry</p> <a class="leaf-button color-d71920" href="/en_hk/business/solutions/iot/ics-ot.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/solutions/iot/ics-ot.html">Electric Utility</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Electric Utility</div> <p class="copy">ICS/OT Security for the electric utility</p> <a class="leaf-button color-d71920" href="/en_hk/business/solutions/iot/ics-ot.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="https://vicone.com/en" target="_blank" rel="noopener noreferrer">Automotive</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Automotive</div> <a class="leaf-button color-d71920" href="https://vicone.com/en" target="_blank" rel="noopener noreferrer">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/solutions/iot/enterprise-5g-iot.html">5G Networks</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">5G Networks</div> <a class="leaf-button color-d71920" href="/en_hk/business/solutions/iot/enterprise-5g-iot.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/small-business/platform.html">Small & Midsized Business Security</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Small & Midsized Business Security</div> <p class="copy">Stop threats with easy-to-use solutions designed for your growing business</p> <a class="leaf-button color-d71920" href="/en_hk/small-business/platform.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> </ul> </li> <li> <!-- Level 0, top menu --> <div class="label">Platform</div> <ul class="sub-menu nav-level-1"> <li> <div class="label branch"> <a class="menu-link" href="/en_hk/business/products/one-platform.html">Vision One Platform</a> </div> <ul class="branch nav-item-2"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/one-platform.html">Vision One Platform</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="subtitle">Trend Vision One</div> <div class="title">Our Unified Platform</div> <p class="copy">Bridge threat protection and cyber risk management</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/one-platform.html">Learn more</a> </div> <div class="leaf-image"> <img src="/content/dam/trendmicro/global/en/core/images/console-images/navigation/trend-vision-one-laptop-console-nav.svg"/> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/technologies/ai-companion.html">AI Companion</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Trend Vision One Companion</div> <p class="copy">Your generative AI cybersecurity assistant</p> <a class="leaf-button color-d71920" href="/en_hk/business/technologies/ai-companion.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/attack-surface-management.html">Attack Surface Management</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Attack Surface Management</div> <p class="copy">Stop breaches before they happen</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/attack-surface-management.html">Learn more</a> </div> <div class="leaf-image"> <img src="https://trendmicro.scene7.com/is/image/trendmicro/asrm-console-shot?scl=1.0&qlt=95&fmt=webp-alpha"/> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/detection-response/xdr.html">XDR (Extended Detection & Response)</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">XDR (Extended Detection & Response)</div> <p class="copy">Stop adversaries faster with a broader perspective and better context to hunt, detect, investigate, and respond to threats from a single platform</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/detection-response/xdr.html">Learn more</a> </div> <div class="leaf-image"> <img src="https://trendmicro.scene7.com/is/image/trendmicro/xdr-product-console-shot?scl=1.0&qlt=95&fmt=webp-alpha"/> </div> </li> </ul> </li> <li> <div class="label branch"> <a class="menu-link" href="/en_hk/business/products/hybrid-cloud.html">Cloud Security</a> </div> <ul class="branch nav-item-2"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/hybrid-cloud.html">Cloud Security</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="subtitle">Trend Vision One™</div> <div class="title">Cloud Security Overview</div> <p class="copy">The most trusted cloud security platform for developers, security teams, and businesses</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/hybrid-cloud.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/endpoint-security/workload-security.html">Workload Security</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Workload Security</div> <p class="copy">Secure your data center, cloud, and containers without compromising performance by leveraging a cloud security platform with CNAPP capabilities</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/endpoint-security/workload-security.html">Learn more</a> </div> <div class="leaf-image"> <img src="https://trendmicro.scene7.com/is/image/trendmicro/cloud-one-workload-security-console-shot?scl=1.0&qlt=95&fmt=webp-alpha"/> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/hybrid-cloud/cloud-one-container-image-security.html">Container Security</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Container Security</div> <p class="copy">Simplify security for your cloud-native applications with advanced container image scanning, policy-based admission control, and container runtime protection</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/hybrid-cloud/cloud-one-container-image-security.html">Learn more</a> </div> <div class="leaf-image"> <img src="https://trendmicro.scene7.com/is/image/trendmicro/cloud-one-container-console-shot?scl=1.0&qlt=95&fmt=webp-alpha"/> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/hybrid-cloud/cloud-one-file-storage-security.html">File Security</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">File Security</div> <p class="copy">Protect application workflow and cloud storage against advanced threats</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/hybrid-cloud/cloud-one-file-storage-security.html">Learn more</a> </div> <div class="leaf-image"> <img src="https://trendmicro.scene7.com/is/image/trendmicro/cloud-one-file-storage-console-shot?scl=1.0&qlt=95&fmt=webp-alpha"/> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/detection-response/attack-surface-management.html">Attack Surface Risk Management for Cloud</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Attack Surface Risk Management for Cloud</div> <p class="copy">Cloud asset discovery, vulnerability prioritization, Cloud Security Posture Management, and Attack Surface Management all in one</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/detection-response/attack-surface-management.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/detection-response/xdr.html">XDR for Cloud</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">XDR for Cloud</div> <p class="copy">Extend visibility to the cloud and streamline SOC investigations</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/detection-response/xdr.html">Learn more</a> </div> <div class="leaf-image"> <img src="https://trendmicro.scene7.com/is/image/trendmicro/xdr-product-console-shot?scl=1.0&qlt=95&fmt=webp-alpha"/> </div> </li> </ul> </li> </ul> </li> <li> <div class="label branch"> <a class="menu-link" href="/en_hk/business/products/endpoint-security.html">Endpoint Security</a> </div> <ul class="branch nav-item-2"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/endpoint-security.html">Endpoint Security</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Endpoint Security Overview</div> <p class="copy">Defend the endpoint through every stage of an attack</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/endpoint-security.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/detection-response/xdr.html">XDR for Endpoint</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">XDR for Endpoint</div> <p class="copy">Stop adversaries faster with a broader perspective and better context to hunt, detect, investigate, and respond to threats from a single platform</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/detection-response/xdr.html">Learn more</a> </div> <div class="leaf-image"> <img src="https://trendmicro.scene7.com/is/image/trendmicro/xdr-product-console-shot?scl=1.0&qlt=95&fmt=webp-alpha"/> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/endpoint-security/workload-security.html">Workload Security</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Workload Security</div> <p class="copy">Optimized prevention, detection, and response for endpoints, servers, and cloud workloads</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/endpoint-security/workload-security.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/iot/industrial-endpoint-security.html">Industrial Endpoint Security</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Industrial Endpoint Security</div> <a class="leaf-button color-d71920" href="/en_hk/business/products/iot/industrial-endpoint-security.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/user-protection/sps/mobile-security-enterprise.html">Mobile Security</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Mobile Security</div> <p class="copy">On-premises and cloud protection against malware, malicious applications, and other mobile threats</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/user-protection/sps/mobile-security-enterprise.html">Learn more</a> </div> <div class="leaf-image"> <img src="https://trendmicro.scene7.com/is/image/trendmicro/sps-mobile-security-enterprise-console-shot?scl=1.0&qlt=95&fmt=webp-alpha"/> </div> </li> </ul> </li> </ul> </li> <li> <div class="label branch"> <a class="menu-link" href="/en_hk/business/products/network.html">Network Security</a> </div> <ul class="branch nav-item-2"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/network.html">Network Security</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Network Security Overview</div> <p class="copy">Expand the power of XDR with network detection and response</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/network.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/detection-response/xdr.html">XDR for Network</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">XDR for Network</div> <p class="copy">Stop adversaries faster with a broader perspective and better context to hunt, detect, investigate, and respond to threats from a single platform</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/detection-response/xdr.html">Learn more</a> </div> <div class="leaf-image"> <img src="https://trendmicro.scene7.com/is/image/trendmicro/xdr-product-console-shot?scl=1.0&qlt=95&fmt=webp-alpha"/> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/network/intrusion-prevention.html">Network Intrusion Prevention (IPS)</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Network Intrusion Prevention (IPS)</div> <p class="copy">Protect against known, unknown, and undisclosed vulnerabilities in your network</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/network/intrusion-prevention.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/network/advanced-threat-protection.html">Breach Detection System (BDS)</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Breach Detection System (BDS)</div> <p class="copy">Detect and respond to targeted attacks moving inbound, outbound, and laterally</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/network/advanced-threat-protection.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/network/zero-trust-secure-access.html">Secure Service Edge (SSE)</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Secure Service Edge (SSE)</div> <p class="copy">Redefine trust and secure digital transformation with continuous risk assessments</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/network/zero-trust-secure-access.html">Learn more</a> </div> <div class="leaf-image"> <img src="https://trendmicro.scene7.com/is/image/trendmicro/zero-trust-access-console-shot?scl=1.0&qlt=95&fmt=webp-alpha"/> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/iot/industrial-network-security.html">Industrial Network Security</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Industrial Network Security</div> <a class="leaf-button color-d71920" href="/en_hk/business/products/iot/industrial-network-security.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/solutions/iot/enterprise-5g-iot.html">5G Network Security</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">5G Network Security</div> <a class="leaf-button color-d71920" href="/en_hk/business/solutions/iot/enterprise-5g-iot.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> </ul> </li> <li> <div class="label branch"> <a class="menu-link" href="/en_hk/business/products/email-security.html">Email Security</a> </div> <ul class="branch nav-item-2"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/email-security.html">Email Security</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Email Security</div> <p class="copy">Stop phishing, malware, ransomware, fraud, and targeted attacks from infiltrating your enterprise</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/email-security.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/user-protection/sps/email-and-collaboration.html">Email and Collaboration Security</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="subtitle">Trend Vision One™</div> <div class="title">Email and Collaboration Security</div> <p class="copy">Stop phishing, ransomware, and targeted attacks on any email service including Microsoft 365 and Google Workspace</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/user-protection/sps/email-and-collaboration.html">Learn more</a> </div> <div class="leaf-image"> <img src="https://trendmicro.scene7.com/is/image/trendmicro/email-security-console-shot?scl=1.0&qlt=95&fmt=webp-alpha"/> </div> </li> </ul> </li> </ul> </li> <li> <div class="label branch"> <a class="menu-link" href="/en_hk/business/solutions/iot/ics-ot.html">OT Security</a> </div> <ul class="branch nav-item-2"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/solutions/iot/ics-ot.html">OT Security</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">OT Security</div> <p class="copy">Learn about solutions for ICS / OT security.</p> <a class="leaf-button color-d71920" href="/en_hk/business/solutions/iot/ics-ot.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/detection-response/xdr.html">XDR for OT</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">XDR for OT</div> <p class="copy">Stop adversaries faster with a broader perspective and better context to hunt, detect, investigate, and respond to threats from a single platform</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/detection-response/xdr.html">Learn more</a> </div> <div class="leaf-image"> <img src="https://trendmicro.scene7.com/is/image/trendmicro/xdr-product-console-shot?scl=1.0&qlt=95&fmt=webp-alpha"/> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/iot/industrial-network-security.html">Industrial Network Security</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Industrial Network Security</div> <a class="leaf-button color-d71920" href="/en_hk/business/products/iot/industrial-network-security.html">Industrial Network Security</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/content/trendmicro/en_hk/business/products/iot/industrial-endpoint-security">Industrial Endpoint Security</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Industrial Endpoint Security</div> <a class="leaf-button color-d71920" href="/content/trendmicro/en_hk/business/products/iot/industrial-endpoint-security">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/one-platform/threat-insights.html">Threat Insights</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Threat Insights</div> <p class="copy">See threats coming from miles away</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/one-platform/threat-insights.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/identity.html">Identity Security</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Identity Security</div> <p class="copy">End-to-end identity security from identity posture management to detection and response</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/identity.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products/sovereign-private-cloud.html">On-Premises Data Sovereignty</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">On-Premises Data Sovereignty</div> <p class="copy">Prevent, detect, respond and protect without compromising data sovereignty</p> <a class="leaf-button color-d71920" href="/en_hk/business/products/sovereign-private-cloud.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/products.html">All Products, Services, and Trials</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">All Products, Services, and Trials</div> <a class="leaf-button color-d71920" href="/en_hk/business/products.html">Learn more</a> </div> <div class="leaf-image"> <img src="https://trendmicro.scene7.com/is/image/trendmicro/all-products-console-shot?scl=1.0&qlt=95&fmt=webp-alpha"/> </div> </li> </ul> </li> </ul> </li> <li> <!-- Level 0, top menu --> <div class="label">Research</div> <ul class="sub-menu nav-level-1"> <li> <div class="label branch"> <a class="menu-link" href="/en_hk/about/threat-research.html">Research</a> </div> <ul class="branch nav-item-2"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/about/threat-research.html">Research</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Research</div> <a class="leaf-button color-d71920" href="/en_hk/about/threat-research.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/research.html">Research, News, and Perspectives</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Research, News, and Perspectives</div> <a class="leaf-button color-d71920" href="/en_hk/research.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="https://www.trendmicro.com/vinfo/hk/security/research-and-analysis/">Research and Analysis</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Research and Analysis</div> <a class="leaf-button color-d71920" href="https://www.trendmicro.com/vinfo/hk/security/research-and-analysis/">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="https://www.trendmicro.com/vinfo/hk/security/news/">Security News</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Security News</div> <a class="leaf-button color-d71920" href="https://www.trendmicro.com/vinfo/hk/security/news/">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/zero-day-initiative/about.html">Zero Day Initiatives (ZDI)</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Zero Day Initiatives (ZDI)</div> <a class="leaf-button color-d71920" href="/en_hk/zero-day-initiative/about.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> </ul> </li> </ul> </li> <li> <!-- Level 0, top menu --> <div class="label">Services</div> <ul class="sub-menu nav-level-1"> <li> <div class="label branch"> <a class="menu-link" href="/en_hk/business/services/service-one.html">Our Services</a> </div> <ul class="branch nav-item-2"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/services/service-one.html">Our Services</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Our Services</div> <a class="leaf-button color-d71920" href="/en_hk/business/services/service-one.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/services/service-one.html">Service Packages</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Service Packages</div> <p class="copy">Augment security teams with 24/7/365 managed detection, response, and support</p> <a class="leaf-button color-d71920" href="/en_hk/business/services/service-one.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/services/managed-xdr.html">Managed XDR</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Managed XDR</div> <p class="copy">Augment threat detection with expertly managed detection and response (MDR) for email, endpoints, servers, cloud workloads, and networks</p> <a class="leaf-button color-d71920" href="/en_hk/business/services/managed-xdr.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label branch"> <a class="menu-link" href="/en_hk/business/services/incident-response.html">Incident Response</a> </div> <ul class="branch nav-item-3"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/services/incident-response.html">Incident Response</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Incident Response</div> <p class="copy">Our trusted experts are on call whether you're experiencing a breach or looking to proactively improve your IR plans</p> <a class="leaf-button color-d71920" href="/en_hk/business/services/incident-response.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/services/incident-response/insurance-law.html">Insurance Carriers and Law Firms</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Insurance Carriers and Law Firms</div> <p class="copy">Stop breaches with the best response and detection technology on the market and reduce clients’ downtime and claim costs</p> <a class="leaf-button color-d71920" href="/en_hk/business/services/incident-response/insurance-law.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/services/support-services.html">Support Services</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Support Services</div> <a class="leaf-button color-d71920" href="/en_hk/business/services/support-services.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> </ul> </li> </ul> </li> <li> <!-- Level 0, top menu --> <div class="label">Partners</div> <ul class="sub-menu nav-level-1"> <li> <div class="label branch"> <a class="menu-link" href="/en_hk/partners/program.html">Partner Program</a> </div> <ul class="branch nav-item-2"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/partners/program.html">Partner Program</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Partner Program Overview</div> <p class="copy">Grow your business and protect your customers with the best-in-class complete, multilayered security</p> <a class="leaf-button color-d71920" href="/en_hk/partners/program.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/partners/competencies.html">Partner Competencies</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Partner Competencies</div> <p class="copy">Stand out to customers with competency endorsements that showcase your expertise</p> <a class="leaf-button color-d71920" href="/en_hk/partners/competencies.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/partners/partner-stories.html">Partner Successes</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Partner Successes</div> <a class="leaf-button color-d71920" href="/en_hk/partners/partner-stories.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/partners/program/managed-security-service-provider.html">Managed Security Service Provider</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Managed Security Service Provider</div> <p class="copy">Deliver modern security operations services with our industry-leading XDR</p> <a class="leaf-button color-d71920" href="/en_hk/partners/program/managed-security-service-provider.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/partners/program/managed-service-provider.html">Managed Service Provider</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Managed Service Provider</div> <p class="copy">Partner with a leading expert in cybersecurity, leverage proven solutions designed for MSPs</p> <a class="leaf-button color-d71920" href="/en_hk/partners/program/managed-service-provider.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> </ul> </li> <li> <div class="label branch"> <a class="menu-link" href="/en_hk/partners/alliance-partners.html">Alliance Partners</a> </div> <ul class="branch nav-item-2"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/partners/alliance-partners.html">Alliance Partners</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Alliance Partners</div> <p class="copy">We work with the best to help you optimize performance and value</p> <a class="leaf-button color-d71920" href="/en_hk/partners/alliance-partners.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/partners/alliance-partners/technology.html">Technology Alliance Partners</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Technology Alliance Partners</div> <a class="leaf-button color-d71920" href="/en_hk/partners/alliance-partners/technology.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/partners/alliance-partners/explore-alliance-partners.html">Find Alliance Partners</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Find Alliance Partners</div> <a class="leaf-button color-d71920" href="/en_hk/partners/alliance-partners/explore-alliance-partners.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> </ul> </li> <li> <div class="label branch"> <a class="menu-link" href="/en_hk/partners/resources.html">Partner Resources</a> </div> <ul class="branch nav-item-2"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/partners/resources.html">Partner Resources</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Partner Resources</div> <p class="copy">Discover resources designed to accelerate your business’s growth and enhance your capabilities as a Trend Micro partner</p> <a class="leaf-button color-d71920" href="/en_hk/partners/resources.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="https://partner.trendmicro.com/" target="_blank" rel="noopener noreferrer">Partner Portal Login</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Partner Portal Login</div> <a class="leaf-button color-d71920" href="https://partner.trendmicro.com/" target="_blank" rel="noopener noreferrer">Login</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/partners/campus.html">Trend Campus</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Trend Campus</div> <p class="copy">Accelerate your learning with Trend Campus, an easy-to-use education platform that offers personalized technical guidance</p> <a class="leaf-button color-d71920" href="/en_hk/partners/campus.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/partners/co-selling.html">Co-Selling</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Co-Selling</div> <p class="copy">Access collaborative services designed to help you showcase the value of Trend Vision One™ and grow your business</p> <a class="leaf-button color-d71920" href="/en_hk/partners/co-selling.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="https://partner.trendmicro.com/pr-register-home/" target="_blank" rel="noopener noreferrer">Become a Partner</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Become a Partner</div> <a class="leaf-button color-d71920" href="https://partner.trendmicro.com/pr-register-home/" target="_blank" rel="noopener noreferrer">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="https://partner.trendmicro.com/partner-locator-home/" target="_blank" rel="noopener noreferrer">Find Partners</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Find Partners</div> <p class="copy">Locate a partner from whom you can purchase Trend Micro solutions</p> <a class="leaf-button color-d71920" href="https://partner.trendmicro.com/partner-locator-home/" target="_blank" rel="noopener noreferrer">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> </ul> </li> <li> <!-- Level 0, top menu --> <div class="label">Company</div> <ul class="sub-menu nav-level-1"> <li> <div class="label branch"> <a class="menu-link" href="/en_hk/about/why-trend-micro.html">Why Trend Micro</a> </div> <ul class="branch nav-item-2"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/about/why-trend-micro.html">Why Trend Micro</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Why Trend Micro</div> <a class="leaf-button color-d71920" href="/en_hk/about/why-trend-micro.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/about/customer-stories.html">Customer Success Stories</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Customer Success Stories</div> <a class="leaf-button color-d71920" href="/en_hk/about/customer-stories.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/content/trendmicro/en_hk/about/human-connections">The Human Connection</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">The Human Connection</div> <a class="leaf-button color-d71920" href="/content/trendmicro/en_hk/about/human-connections">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/about/industry-recognition.html">Industry Accolades</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Industry Accolades</div> <a class="leaf-button color-d71920" href="/en_hk/about/industry-recognition.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/partners/alliance-partners.html">Strategic Alliances</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Strategic Alliances</div> <a class="leaf-button color-d71920" href="/en_hk/partners/alliance-partners.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> </ul> </li> <li> <div class="label branch"> <a class="menu-link" href="/en_hk/about.html">About Us</a> </div> <ul class="branch nav-item-2"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/about.html">About Us</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">About Us</div> <a class="leaf-button color-d71920" href="/en_hk/about.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/about/trust-center.html">Trust Center</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Trust Center</div> <a class="leaf-button color-d71920" href="/en_hk/about/trust-center.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/about/history-vision-values.html">History</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">History</div> <a class="leaf-button color-d71920" href="/en_hk/about/history-vision-values.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/about/diversity-inclusion.html">Diversity, Equity and Inclusion</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Diversity, Equity and Inclusion</div> <a class="leaf-button color-d71920" href="/en_hk/about/diversity-inclusion.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/about/corporate-social-responsibility.html">Corporate Social Responsibility</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Corporate Social Responsibility</div> <a class="leaf-button color-d71920" href="/en_hk/about/corporate-social-responsibility.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/about/leaders.html">Leadership</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Leadership</div> <a class="leaf-button color-d71920" href="/en_hk/about/leaders.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/about/leading-experts.html">Security Experts</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Security Experts</div> <a class="leaf-button color-d71920" href="/en_hk/about/leading-experts.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/initiative-education.html">Internet Safety and Cybersecurity Education</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Internet Safety and Cybersecurity Education</div> <a class="leaf-button color-d71920" href="/en_hk/initiative-education.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/about/legal.html">Legal</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Legal</div> <a class="leaf-button color-d71920" href="/en_hk/about/legal.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_us/about/investor-relations.html" target="_blank" rel="noopener noreferrer">Investors</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Investors</div> <a class="leaf-button color-d71920" href="/en_us/about/investor-relations.html" target="_blank" rel="noopener noreferrer">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/business/campaigns/formula-e.html">Formula E Racing</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Formula E Racing</div> <a class="leaf-button color-d71920" href="/en_hk/business/campaigns/formula-e.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> </ul> </li> <li> <div class="label branch"> <a class="menu-link" href="https://newsroom.trendmicro.com/" target="_blank" rel="noopener noreferrer">Connect With Us</a> </div> <ul class="branch nav-item-2"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li> <div class="label leaf"> <a class="menu-link" href="https://newsroom.trendmicro.com/" target="_blank" rel="noopener noreferrer">Connect With Us</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Connect With Us</div> <a class="leaf-button color-d71920" href="https://newsroom.trendmicro.com/" target="_blank" rel="noopener noreferrer">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/about/newsroom.html">Newsroom</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Newsroom</div> <a class="leaf-button color-d71920" href="/en_hk/about/newsroom.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/about/events.html">Events</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Events</div> <a class="leaf-button color-d71920" href="/en_hk/about/events.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/about/careers.html">Careers</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Careers</div> <a class="leaf-button color-d71920" href="/en_hk/about/careers.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/about/webinars.html">Webinars</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Webinars</div> <a class="leaf-button color-d71920" href="/en_hk/about/webinars.html">Learn more</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> </ul> </li> <li> <div class="label branch"> <a class="menu-link" href="/en_hk/about/compare.html">Compare Trend Micro</a> </div> <ul class="branch nav-item-2"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/about/compare.html">Compare Trend Micro</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Compare Trend Micro</div> <p class="copy">See how Trend outperforms the competition</p> <a class="leaf-button color-d71920" href="/en_hk/about/compare.html">Let's go</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/about/compare/trend-vs-crowdstrike.html">vs. Crowdstrike</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Trend Micro vs. Crowdstrike</div> <p class="copy">Crowdstrike provides effective cybersecurity through its cloud-native platform, but its pricing may stretch budgets, especially for organizations seeking cost-effective scalability through a true single platform</p> <a class="leaf-button color-d71920" href="/en_hk/about/compare/trend-vs-crowdstrike.html">Let's go</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/about/compare/trend-vs-microsoft.html">vs. Microsoft</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Trend Micro vs. Microsoft</div> <p class="copy">Microsoft offers a foundational layer of protection, yet it often requires supplemental solutions to fully address customers' security problems</p> <a class="leaf-button color-d71920" href="/en_hk/about/compare/trend-vs-microsoft.html">Let's go</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> <li> <div class="label leaf"> <a class="menu-link" href="/en_hk/about/compare/trend-vs-palo-alto-networks.html">vs. Palo Alto Networks</a> </div> <ul class="leaf nav-item-leaf"> <!-- This fake child menu should be a desktop enhancement only. Mobile never uses it --> <li class="desktop-leaf-child"> <div class="desktop-leaf-child-text"> <div class="title">Trend Micro vs. Palo Alto Networks</div> <p class="copy">Palo Alto Networks delivers advanced cybersecurity solutions, but navigating its comprehensive suite can be complex and unlocking all capabilities requires significant investment</p> <a class="leaf-button color-d71920" href="/en_hk/about/compare/trend-vs-palo-alto-networks.html">Let's go</a> </div> <div class="leaf-image"> </div> </li> </ul> </li> </ul> </li> </ul> </li> </ul> </div> <div class="list-wrapper drop-down-menu-2"> <button type="button" class="back-one-level"> <span>Back</span> </button> <div class="sub-menu-wrapper"></div> </div> <div class="list-wrapper drop-down-menu-3"> <button type="button" class="back-one-level"> <span>Back</span> </button> <div class="sub-menu-wrapper"></div> </div> <div class="list-wrapper drop-down-menu-4"> <button type="button" class="back-one-level"> <span>Back</span> </button> <div class="sub-menu-wrapper"></div> </div> <div class="list-wrapper drop-down-menu-5"> <button type="button" class="back-one-level"> <span>Back</span> </button> <div class="sub-menu-wrapper"></div> </div> <div class="buttonArrayV1"> <ul class="button-array small left-align global-margin-top-none global-margin-bottom-none global-padding-top-none global-padding-bottom-none"> <li class="button-array-list"> <a class="button secondary color-ffffff normal" id="rsg-nav-free-trial-98297c" href="/en_hk/business/products/trials.html"> Free Trials </a> </li> <li class="button-array-list"> <a class="button primary color-d71920 normal" id="rsh-nav-contact-us-cd81f8" href="/en_hk/business/get-info-form.html"> Contact Us </a> </li> </ul> </div> </div> </div> <div class="consumerLink"> <a href="/en_hk/forHome.html">Looking for home solutions?</a> </div> <a href="https://resources.trendmicro.com/GLB-Under-Attack-Form.html" class="under-attack-link">Under Attack?</a> <div class="alerts"> <div class="alertUtilityMenu"> <div class="utility-wrapper alert-top-menu"> <div class="dropDownMenuV1"> <div class="label"><span class="counter">4</span> Alerts</div> <div class="menu"><!--Intentionally left blank--></div> </div> </div> <div class="utility-wrapper alert-sub-menu"> <button type="button" class="back-one-level-utility"> <span>Back</span> </button> <div class="sub-wrapper-content"> <div class="alerts-wrapper"> <div class="alert-buttons"> <div class="alerts-unread-button is-active">Unread</div> <div class="alerts-all-button">All</div> </div> <div class="sub-alerts-wrapper"></div> </div> <ul class="alerts-list"> <li id="alert-8dc677" class="unread"> <div class="copy-wrapper"> <!-- TEXT - now clickable --> <a href="https://www.trendmicro.com/vinfo/hk/security/news/cybercrime-and-digital-threats/understanding-hacktivists-the-overlap-of-ideology-and-cybercrime"> <p class="copy">The rise of hacktivism and cybercrime: how ideological motives drive cyberattacks</p> </a> <span class="material-symbols-outlined">close</span> </div> <!-- CTA TEXT --> <a href="https://www.trendmicro.com/vinfo/hk/security/news/cybercrime-and-digital-threats/understanding-hacktivists-the-overlap-of-ideology-and-cybercrime"> <p class="ctaText">Read more ></p> </a> </li> <li id="alert-6aed0a" class="unread"> <div class="copy-wrapper"> <!-- TEXT - now clickable --> <a href="https://www.trendmicro.com/vinfo/hk/security/news/cybercrime-and-digital-threats/metaverse-or-metaworse-how-the-apple-vision-pro-stacks-up-against-predictions"> <p class="copy">The future of the Metaverse: analyzing security risks in virtual spaces</p> </a> <span class="material-symbols-outlined">close</span> </div> <!-- CTA TEXT --> <a href="https://www.trendmicro.com/vinfo/hk/security/news/cybercrime-and-digital-threats/metaverse-or-metaworse-how-the-apple-vision-pro-stacks-up-against-predictions"> <p class="ctaText">Learn more ></p> </a> </li> <li id="alert-b3ed43" class="unread"> <div class="copy-wrapper"> <!-- TEXT - now clickable --> <a href="https://www.trendmicro.com/vinfo/hk/security/news/cybercrime-and-digital-threats/across-the-span-of-the-spanish-cybercriminal-underground-current-activities-and-trends"> <p class="copy">Exploring the latest trends in the Spanish cybercriminal underground</p> </a> <span class="material-symbols-outlined">close</span> </div> <!-- CTA TEXT --> <a href="https://www.trendmicro.com/vinfo/hk/security/news/cybercrime-and-digital-threats/across-the-span-of-the-spanish-cybercriminal-underground-current-activities-and-trends"> <p class="ctaText">Learn more > </p> </a> </li> <li id="alert-11217f" class="unread"> <div class="copy-wrapper"> <!-- TEXT - now clickable --> <a href="/en_hk/research/25/a/cve-2025-0411-ukrainian-organizations-targeted.html"> <p class="copy">CVE-2025-0411 exploited in attacks on Ukraine</p> </a> <span class="material-symbols-outlined">close</span> </div> <!-- CTA TEXT --> <a href="/en_hk/research/25/a/cve-2025-0411-ukrainian-organizations-targeted.html"> <p class="ctaText">Read the report > </p> </a> </li> </ul> </div> </div> </div> </div> <div class="utilityMenuV1"><div class="utilityMenu utilityMenuV1"> <div class="utility-wrapper standard-utility-wrapper"> <div class="dropDownMenuV1"> <div class="label">Support</div> <div class="menu"> <ul> <li> <a rel="noopener noreferrer" href="https://success.trendmicro.com/en-US/" target="_blank"> Business Support Portal </a> </li> <li> <a href="/en_hk/business/services/support-services/education.html"> Education and Certification </a> </li> <li> <a rel="noopener noreferrer" href="https://success.trendmicro.com/en-US/contactus/" target="_blank"> Contact Support </a> </li> <li> <a rel="noopener noreferrer" href="https://partner.trendmicro.com/partner-locator-home/" target="_blank"> Find a Support Partner </a> </li> </ul> </div> </div> <div class="dropDownMenuV1"> <div class="label">Resources</div> <div class="menu"> <ul> <li> <a href="/en_hk/business/ai.html"> AI Security </a> </li> <li> <a href="/en_hk/about/compare.html"> Trend Micro vs. Competition </a> </li> <li> <a href="https://resources.trendmicro.com/security-assessment-service-us.html"> Cyber Risk Assessments </a> </li> <li> <a href="/en_hk/what-is.html"> What Is? </a> </li> <li> <a href="https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/"> Threat Encyclopedia </a> </li> <li> <a href="/en_hk/business/cyber-insurance.html"> Cyber Insurance </a> </li> <li> <a href="https://www.trendmicro.com/vinfo/hk/security/definition/a"> Glossary of Terms </a> </li> <li> <a href="/en_hk/about/webinars.html"> Webinars </a> </li> </ul> </div> </div> <div class="dropDownMenuV1"> <div class="label">Log In</div> <div class="menu"> <ul> <li> <a rel="noopener noreferrer" href="https://signin.v1.trendmicro.com/" target="_blank"> Vision One </a> </li> <li> <a rel="noopener noreferrer" href="https://success.trendmicro.com/en-US/" target="_blank"> Support </a> </li> <li> <a rel="noopener noreferrer" href="https://partner.trendmicro.com/" target="_blank"> Partner Portal </a> </li> <li> <a rel="noopener noreferrer" href="https://cloudone.trendmicro.com/" target="_blank"> Cloud One </a> </li> <li> <a rel="noopener noreferrer" href="https://tm.login.trendmicro.com/simplesaml/saml2/idp/SSOService.php" target="_blank"> Product Activation and Management </a> </li> <li> <a rel="noopener noreferrer" href="https://signup.cj.com/member/signup/publisher/?cid=1867119#/branded?_k=xaeu3t" target="_blank"> Referral Affiliate </a> </li> </ul> </div> </div> </div> <div class="utility-wrapper active-utility-wrapper"> <button type="button" class="back-one-level-utility"> <span>Back</span> </button> <div class="sub-utility-wrapper"></div> </div> </div> </div> </div> </nav> </header> <div class="search"> <script type="text/javascript" src="//customer.cludo.com/scripts/bundles/search-script.js"></script> <script type="text/javascript"> var cludoSettings = {}; if( undefined === window.utag_data ) { cludoSettings.cludo_language = 'en'; } else { switch (window.utag_data.language_code) { // Cludo dropped the ball on this one case 'ja_jp': cludoSettings.cludo_language = 'jp'; break; case 'in_id': cludoSettings.cludo_language = 'id'; break; default: cludoSettings.cludo_language = window.utag_data.language_code.substring(0, 2); // First two letters are the language break; } } cludoSettings.settingsObject = { customerId: 296, engineId: 2194, searchUrl: "/en_hk/common/cse.html", searchInputs: ["cludo-search-form","cludo-search-form-mobile","cludo-search-content-form"], initSearchBoxText: "", language: cludoSettings.cludo_language, //endlessScroll: {stopAfterPage:3, resultsPerPage:10, bottomOffset: 145}, //translateSearchTemplates: true, loading: "<div class='loader'></div>" }; </script> <span class="material-symbols-outlined search-back-arrow">arrow_back</span> <div class="inner-search-wrap"> <span class="material-symbols-outlined search-icon">search</span> <form class="main-menu-search" aria-label="Search Trend Micro"> <div class="main-menu-search__field-wrapper" id="cludo-search-form"> <table class="gsc-search-box"> <tbody> <tr> <td class="gsc-input"> <input type="text" class="gsc-input-field" name="search" title="search" placeholder="Search"/> </td> </tr> </tbody> </table> </div> </form> <span class="material-symbols-outlined search-clear-button">close</span> </div> </div> </div> <section class="folder-indicators slider"> <div class="folder-indicators__wrapper"> <p class="folder-indicators__title">Content has been added to your Folio</p> <div class="folder-indicators__button-wrapper"> <button class="folder-indicators__button counter" id="counter-folder"> Go to Folio (<span>0</span>) </button> <button class="folder-indicators__button close"><span class="material-symbols-outlined close-folio-message">close</span></button> </div> </div> </section></div> <div class="root responsivegrid"> <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 "> <div class="articleBodyNoHero aem-GridColumn aem-GridColumn--default--12"><div class="research-layout article container" role="contentinfo"> <article class="research-layout--wrapper row" data-article-pageID="1298308672"> <div class="col-xs-12 col-md-12 one-column"> <div class="col-xs-12 col-md-12"> <div class="article-details" role="heading"> <span class="article-details__bar" role="img"></span> <p class="article-details__display-tag">Exploits & Vulnerabilities</p> <h1 class="article-details__title">CVE-2025-0411: Ukrainian Organizations Targeted in Zero-Day Campaign and Homoglyph Attacks</h1> <p class="article-details__description">The Trend ZDI team offers an analysis on how CVE-2025-0411, a zero-day vulnerability in 7-Zip, was actively exploited to target Ukrainian organizations in a SmokeLoader campaign involving homoglyph attacks.</p> <p class="article-details__author-by">By: Peter Girnus <time class="article-details__date">February 04, 2025</time> <span>Read time: </span><span class="eta"></span> (<span class="words"></span> words) </p> <div class="article-details__icons"> <!--Add This--> <div class="a2a_kit a2a_default_style" data-a2a-icon-color="#717172"> <a class="a2a_dd addthis_link" href="https://www.addtoany.com/share"> <img src="/etc.clientlibs/trendresearch/clientlibs/clientlib-trendresearch/resources/img/share-more.svg" class="svg-icon" alt="Share"/> </a> <a class="a2a_button_print addthis_link"> <img src="/etc.clientlibs/trendresearch/clientlibs/clientlib-trendresearch/resources/img/printer.svg" class="svg-icon" alt="Print"/> </a> </div> <!--Add to Folio--> <div class="add-to-folio tooltip"> <span class="icon-folio-thin"></span> <div class="right"> <p>Save to Folio</p> <i></i> </div> </div> <!--Subscribe--> <div class="subscribe"> </div> </div> </div> </div> </div> <hr class="research-layout-divider"/> <main class="main--content col-xs-12 col-lg-8 col-lg-push-2"> <div> </div> <div class="richText"> <div> <h1><span class="body-subhead-title">Summary</span></h1> <ul> <li><span class="rte-red-bullet">In September, 2024 the Trend Zero Day Initiative™ (ZDI) Threat Hunting team identified the exploitation of a 7-Zip zero-day vulnerability used in a SmokeLoader malware campaign targeting Ukrainian entities.</span></li> <li><span class="rte-red-bullet">The vulnerability, CVE-2025-0411, was disclosed to 7-Zip creator Igor Pavlov, leading to the release of a patch in version 24.09 on November 30, 2024.</span></li> <li><span class="rte-red-bullet">CVE-2025-0411 allows the bypassing of Windows Mark-of-the-Web protections by double archiving files, thus preventing necessary security checks and allowing the execution of malicious content.</span></li> <li><span class="rte-red-bullet">The vulnerability was actively exploited by Russian cybercrime groups through spear-phishing campaigns, using homoglyph attacks to spoof document extensions and trick users and the Windows Operating System into executing malicious files.</span></li> <li><span class="rte-red-bullet">The vulnerability was likely exploited as a cyberespionage campaign against Ukrainian government and civilian organizations as part of the ongoing Russo-Ukraine conflict.</span></li> <li><span class="rte-red-bullet">We provide recommendations for organizations to proactively secure their systems. This includes updating 7-Zip to at least version 24.09, implementing strict email security measures, and conducting employee training on phishing (including homoglyph attacks).</span></li> </ul> <h1><span class="body-subhead-title">Introduction</span></h1> <p>On September 25, 2024, the <a href="https://www.zerodayinitiative.com/blog/2024/12/10/the-december-2024-security-update-review">Trend ZDI </a>Threat Hunting team identified a zero-day vulnerability exploited in-the-wild and associated with the deployment of the loader malware known as <a href="https://attack.mitre.org/software/S0226/">SmokeLoader</a>. This vulnerability is believed to be used by Russian cybercrime groups to target both governmental and non-governmental organizations in Ukraine, with cyberespionage being the most likely purpose of these attacks as part of the ongoing Russo-Ukrainian conflict. The exploitation involves the use of compromised email accounts and a zero-day vulnerability existing in the archiver tool 7-Zip (<a href="https://www.zerodayinitiative.com/advisories/ZDI-25-045/">CVE-2025-0411</a>), which was manipulated through homoglyph attacks (which we will also define and explain in this blog entry).</p> <p>Following initial analysis and the development of a proof-of-concept (PoC), we formally disclosed the vulnerability to Igor Pavlov, the creator of 7-Zip, on October 1, 2024. The issue was subsequently addressed, with 7-Zip releasing a patch as part of <a href="https://sourceforge.net/p/sevenzip/discussion/45797/thread/b95432c7ac/">version 24.09</a> on November 30, 2024.</p> <p>This entry will first examine CVE-2025-0411 in a theoretical context, based on the PoC submitted to 7-Zip. Subsequently, we will analyze the real-world exploitation of this vulnerability as a zero-day in active use.</p> <h1><span class="body-subhead-title">CVE-2025-0411: 7-Zip Mark-of-the-Web Bypass Vulnerability</span></h1> <p>When a user downloads a file from an untrusted source, such as the internet, Microsoft Windows implements a security feature known as the Mark-of-the-Web (MoTW). This feature marks the local copy of the file by adding an NTFS Alternate Data Stream (ADS) named <i>Zone.Identifier</i>. Within this stream, the text <i>ZoneId=3</i> is embedded, signifying that the file came from an untrusted zone, specifically the internet. This ensures that untrsuted files are not accidentally executed and allows the Windows operating system to perform extra security checks through Microsoft Defender SmartScreen.</p> <p>CVE-2025-0411 allows threat actors to bypass Windows MoTW protections by double archiving contents using 7-Zip. Double archiving involves incapsulating an archive within an archive.</p> </div> </div> <div class="image"> <figure class="image-figure"> <a class="bs-modal" id="4f73ad" data-modal-title="Figure 1. The Zone.Identifier of the outer encapsulated archive" href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig1.png"> <img src="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig1.png" alt="Figure 1. The Zone.Identifier of the outer encapsulated archive"/> </a> <div class="caption-image-container "> <figcaption>Figure 1. The Zone.Identifier of the outer encapsulated archive</figcaption> <div class="download-anchor-wrapper"> <a href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig1.png" class="download-anchor" download> <span class="material-symbols-outlined">download</span> </a> </div> </div> </figure> </div> <div> <div class="image"> <figure class="image-figure"> <a class="bs-modal" id="d46ea1" data-modal-title="Figure 2. The Properties view of a file containing a MoTW" href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig2.png"> <img src="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig2.png" alt="Figure 2. The Properties view of a file containing a MoTW"/> </a> <div class="caption-image-container "> <figcaption>Figure 2. The Properties view of a file containing a MoTW</figcaption> <div class="download-anchor-wrapper"> <a href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig2.png" class="download-anchor" download> <span class="material-symbols-outlined">download</span> </a> </div> </div> </figure> </div> <div class="richText"> <div> <p>An MoTW designation helps prevent the automatic execution of potentially harmful scripts or applications by notifying the system and user to treat the file with caution and then directing it to perform additional analysis via Windows Defender SmartScreen.</p> </div> </div> <div class="image"> <figure class="image-figure"> <a class="bs-modal" id="cede78" data-modal-title="Figure 3. Windows Defender SmartScreen Security warning prompted by MoTW" href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig3.png"> <img src="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig3.png" alt="Figure 3. Windows Defender SmartScreen Security warning prompted by MoTW"/> </a> <div class="caption-image-container "> <figcaption>Figure 3. Windows Defender SmartScreen Security warning prompted by MoTW</figcaption> <div class="download-anchor-wrapper"> <a href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig3.png" class="download-anchor" download> <span class="material-symbols-outlined">download</span> </a> </div> </div> </figure> </div> <div class="richText"> <div> <p>Windows MoTW is an important part of the Windows security architecture and is needed for other key Windows protection mechanisms to function, such as:</p> <ul> <li><span class="rte-red-bullet">Windows Defender SmartScreen, which examines files based on reputation and signature.</span></li> <li><span class="rte-red-bullet">Microsoft Office Protected View, which protects users from threats such as malicious macros and Dynamic Data Exchange (DDE) attacks.</span></li> </ul> <p>The root cause of CVE-2025-0411 is that prior to version 24.09, 7-Zip did not properly propagate MoTW protections to the content of double-encapsulated archives. This allows threat actors to craft archives containing malicious scripts or executables that will not receive MoTW protections, leaving Windows users vulnerable to attacks.</p> </div> </div> <div class="image"> <figure class="image-figure"> <a id="b7d25c" data-modal-title="Figure 4. PoC demo of CVE-2025-0411 with encapsulated ZIP archive" href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig4.png"> <img src="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig4.png" alt="Figure 4. PoC demo of CVE-2025-0411 with encapsulated ZIP archive"/> </a> <div class="caption-image-container "> <figcaption>Figure 4. PoC demo of CVE-2025-0411 with encapsulated ZIP archive</figcaption> <div class="download-anchor-wrapper"> <a href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig4.png" class="download-anchor" download> <span class="material-symbols-outlined">download</span> </a> </div> </div> </figure> </div> <div class="richText"> <div> <p>In Figure 4, the <i>poc.bat</i> file has no MoTW protections since it is encapsulated inside the <i>poc.outer.zip\poc.inner.zip </i>archive. This greatly increases the risk of infection and prevents Microsoft Windows Defender SmartScreen from performing reputation and signature checks.</p> </div> </div> <div class="image"> <figure class="image-figure"> <a class="bs-modal" id="9f9bf6" data-modal-title="Figure 5. Users are compromised once poc.bat is executed" href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig5.png"> <img src="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig5.png" alt="Figure 5. Users are compromised once poc.bat is executed"/> </a> <div class="caption-image-container "> <figcaption>Figure 5. Users are compromised once poc.bat is executed</figcaption> <div class="download-anchor-wrapper"> <a href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig5.png" class="download-anchor" download> <span class="material-symbols-outlined">download</span> </a> </div> </div> </figure> </div> <div class="richText"> <div> <p>Now that we have covered a simple example of CVE-2025-0411, let’s examine how this vulnerability was exploited in the wild by Russian cybercrime groups.</p> <h1><span class="body-subhead-title">CVE-2025-0411 exploited as a Zero Day by Russian cybercrime groups</span></h1> <p>As mentioned in our introduction, we first uncovered this zero-day exploit in the wild on September 25, 2024. This vulnerability was used to target both the Ukrainian government and other Ukrainian organizations in a SmokeLoader campaign that was likely deployed by Russian cybercrime groups.</p> <h2><span class="body-subhead-title"><span class="rte-sub-menu-text">Initial Access: Spearphishing Attachment (T1566.001)</span></span></h2> <p>During our investigation, we uncovered emails originating from multiple Ukranian governing bodies and Ukrainian business accounts targeting both Ukrainian municipal organizations and Ukrainian businesses.</p> </div> </div> <div class="image"> <figure class="image-figure"> <a class="bs-modal" id="0b327e" data-modal-title="Figure 6. Sample phishing email coming from a compromised Ukrainian government email account" href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig6.png"> <img src="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig6b.png" alt="Figure 6. Sample phishing email coming from a compromised Ukrainian government email account"/> </a> <div class="caption-image-container "> <figcaption>Figure 6. Sample phishing email coming from a compromised Ukrainian government email account</figcaption> <div class="download-anchor-wrapper"> <a href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig6b.png" class="download-anchor" download> <span class="material-symbols-outlined">download</span> </a> </div> </div> </figure> </div> <div class="richText"> <div> <p>In Figure 6, we see a 7-Zip attachment (SHA256: ba74ecae43adc78efaee227a0d7170829b9036e5e7f602cf38f32715efa51826) coming from an email account belonging to the <a href="https://uk.wikipedia.org/wiki/%D0%94%D0%B5%D1%80%D0%B6%D0%B0%D0%B2%D0%BD%D0%B0_%D0%B2%D0%B8%D0%BA%D0%BE%D0%BD%D0%B0%D0%B2%D1%87%D0%B0_%D1%81%D0%BB%D1%83%D0%B6%D0%B1%D0%B0_%D0%A3%D0%BA%D1%80%D0%B0%D1%97%D0%BD%D0%B8">State Executive Service of Ukraine (SES)</a>, a former organization within the Ukrainian executive branch, that has now been merged with the <a href="https://minjust.gov.ua/">Ukrainian Ministry of Justice</a>. The recipient of this spear phishing email is the helpdesk of the <a href="https://zaporizhzhia.city/en/places/zaporozhskiy-avtomobilestroitelnyy-zavod">Zaporizhzhia Automobile Building Plant (PrJSC ZAZ)</a> — ZAZ being one of the largest manufacturers of automobiles, trucks, and buses within Ukraine. For some regional context, the Zaporizhzhia Oblast is an important industrial region within Ukraine which experienced some of the most intense fighting between Ukrainian and Russian forces since the start of the conflict in 2022. On March 3, 2022, the fighting culminated in the Russian <a href="https://edition.cnn.com/2022/03/04/europe/ukraine-zaporizhzhia-nuclear-plant-attack-explainer-intl/index.html">capture of the Zaporizhzhia</a> nuclear power plant, raising concerns about a potential nuclear meltdown. </p> </div> </div> <div class="image"> <figure class="image-figure"> <a class="bs-modal" id="d6d1f9" data-modal-title="Figure 7. Email translation from Ukrainian to English" href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig7.png"> <img src="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig7.png" alt="Figure 7. Email translation from Ukrainian to English"/> </a> <div class="caption-image-container "> <figcaption>Figure 7. Email translation from Ukrainian to English</figcaption> <div class="download-anchor-wrapper"> <a href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig7.png" class="download-anchor" download> <span class="material-symbols-outlined">download</span> </a> </div> </div> </figure> </div> <div class="richText"> <div> <p>This email was first uploaded to VirusTotal on September 25, 2024.</p> <h1><span class="body-subhead-title">The exploitation of CVE-2025-0411 via homoglyph attacks</span></h1> <p>Earlier, we discussed a working PoC exploit of CVE-2025-0411 that used a nested archive structure such as <i>poc.outer.zip/poc.inner.zip/poc.bat</i>. In the samples we uncovered as part of the SmokeLoader campaign, the inner ZIP archive deployed a homoglyph attack to spoof a Microsoft Windows Document (.doc) file.</p> <h2><span class="body-subhead-title"><span class="rte-sub-menu-text">What are homoglyph attacks?</span></span></h2> <p>A homoglyph attack is a type of attack incorporating typographic manipulation using similar-looking characters to fool victims into clicking suspicious files or visiting malicious websites. These attacks are commonly used as part of phishing campaigns. where threat actors might use homoglyphs for spoofing legitimate websites to trick users into entering their credentials for credential harvesting. These credentials would then be employed as a pivot point to further compromise an organization.</p> <p>As an example, an attacker may use the Cyrillic letter <i>Es</i> (which looks exactly like the Latin letter <i>С</i> or <i>с</i>) in a domain name such as api-miсrosoft[.]com, with “c” here being the “Es” character instead of the Latin one, to trick users into trusting this domain —perhaps to lure them into entering sensitive details such as usernames and passwords.</p> </div> </div> <div class="image"> <figure class="image-figure"> <a class="bs-modal" id="65e289" data-modal-title="Figure 8. The letter c is replaced with the Cyrillic Es (с) homoglyph" href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig8.png"> <img src="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig8.png" alt="Figure 8. The letter c is replaced with the Cyrillic Es (с) homoglyph"/> </a> <div class="caption-image-container "> <figcaption>Figure 8. The letter c is replaced with the Cyrillic Es (с) homoglyph</figcaption> <div class="download-anchor-wrapper"> <a href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig8.png" class="download-anchor" download> <span class="material-symbols-outlined">download</span> </a> </div> </div> </figure> </div> <div class="richText"> <div> <p>In Figure 8, the potential for deception presented by homoglyph characters is clearly demonstrated. A fully spoofed Microsoft domain has been created by substituting the Latin character “C” with the Cyrillic character “Es” (C). This typographic manipulation effectively misleads individuals into believing that they are accessing a legitimate Microsoft domain, thereby causing them to perceive the login screen as being part of an authentic site.</p> </div> </div> <div class="image"> <figure class="image-figure"> <a class="bs-modal" id="0ab22a" data-modal-title="Figure 9. A real Microsoft login domain" href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig9.png"> <img src="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig9.png" alt="Figure 9. A real Microsoft login domain"/> </a> <div class="caption-image-container "> <figcaption>Figure 9. A real Microsoft login domain</figcaption> <div class="download-anchor-wrapper"> <a href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig9.png" class="download-anchor" download> <span class="material-symbols-outlined">download</span> </a> </div> </div> </figure> </div> <div class="richText"> <div> <p>In Figure 9, the actual Microsoft login domain is depicted, with the actual Latin "C" character.</p> <p>Although this domain features the TLS/SSL lock icon and the Microsoft <i>favicon</i>, these indicators alone are not always enough for verifying the domain's authenticity. A comprehensive analysis of the TLS certificate and additional technical specifics are often essential in substantiating the legitimacy of a domain. However, these technical elements can elude the average web user.</p> <p>Having established an understanding of homoglyph attacks, let’s return to our analysis of the in-the-wild example.</p> <h2><span class="body-subhead-title"><span class="rte-sub-menu-text">In-the-wild: zero-day exploitation through homoglyph attacks</span></span></h2> <p>During this campaign, the threat actors implemented an additional layer of deception to manipulate users into executing the zero-day vulnerability CVE-2025-0411. By employing the Cyrillic character "Es", the attackers designed an inner archive mimicking a .doc<i> </i>file. This strategy effectively misleads users into inadvertently triggering the exploit for CVE-2025-0411, resulting in the contents of the archive being released without MoTW protections. Consequently, this allows for the execution of JavaScript files (.js), Windows Script Files (.wsf), and Windows Shortcut files (.url). I</p> <p>Using an example from the SmokeLoader campaign, <a href="https://www.virustotal.com/gui/search/name%253A%2522%25D0%2594%25D0%25BE%25D0%25BA%25D1%2583%25D0%25BC%25D0%25B5%25D0%25BD%25D1%2582%25D0%25B8%2520%25D1%2582%25D0%25B0%2520%25D0%25BF%25D0%25BB%25D0%25B0%25D1%2582%25D0%25B5%25D0%25B6%25D0%25B8.7z%2522"><i>Документи та платежи.7z</i></a> (84ab6c3e1f2dc98cf4d5b8b739237570416bb82e2edaf078e9868663553c5412), translating to “<i>Documents and payments</i>” in English, serves as the outer zip archive and <a href="https://www.virustotal.com/gui/search/name%253A%25D0%25A1%25D0%25BFi%25D1%2581%25D0%25BE%25D0%25BA.do%25D1%2581"><i>Спiсок.doс</i></a> (7786501e3666c1a5071c9c5e5a019e2bc86a1f169d469cc4bfef2fe339aaf384), translated to “<i>List</i>”, serves as the inner archive. This uses a homoglyph attack where the “c” in the “.doc” extension is a Cyrillic “Es” character.</p> </div> </div> <div class="image"> <figure class="image-figure"> <a class="bs-modal" id="c5de4b" data-modal-title="Figure 10. Hex Comparison between Документи та платежи.7z (outer archive) and Спiсок.doс (homoglyph attack and inner archive)" href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig10.png"> <img src="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig10.png" alt="Figure 10. Hex Comparison between Документи та платежи.7z (outer archive) and Спiсок.doс (homoglyph attack and inner archive)"/> </a> <div class="caption-image-container "> <figcaption>Figure 10. Hex Comparison between Документи та платежи.7z (outer archive) and Спiсок.doс (homoglyph attack and inner archive)</figcaption> <div class="download-anchor-wrapper"> <a href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig10.png" class="download-anchor" download> <span class="material-symbols-outlined">download</span> </a> </div> </div> </figure> </div> <div class="richText"> <div> <p>In Figure 10, we can see a side-by-side comparison of both outer and inner zip archives (which contain the 7-Zip magic bytes <i>\x37\x7A\xBC\xAF\x27\x1C</i>). It is important to note that even though both archives happen to be 7-Zip archives, it does not matter what archive format is used when it comes to the exploitation of CVE-2025-0411.</p> <h2><span class="body-subhead-title"><span class="rte-sub-menu-text">In-the-wild: contents of Спiсок.doс (inner archive)</span></span></h2> <p>Inside Спiсок.doс, the .url file <a href="https://www.virustotal.com/gui/search/name%253A%2522%25D0%259F%25D0%25BB%25D0%25B0%25D1%2582%25D0%25B5%25D0%25B6%25D0%25BD%25D0%25BE%25D0%25B5%2520%25D0%259F%25D0%25BE%25D1%2580%25D1%2583%25D1%2587%25D0%25B5%25D0%25BD%25D0%25B8%25D0%25B5%2520%25D0%25B2%2520i%25D0%25BD%25D0%25BE%25D0%25B7%25D0%25B5%25D0%25BD%25D0%25BE%25D0%25B9%2520%25D0%25B2%25D0%25B0%25D0%25BB%25D1%258E%25D1%2582%25D0%25B5%2520%25D1%2582%25D0%25B0%2520%25D1%2581%25D0%25BE%25D0%25BF%25D1%2580%25D0%25BE%25D0%25B2%25D0%25BE%25D0%25B4i%25D1%2582%25D0%25B5%25D0%25BB%25D1%258C%25D0%25BD%25D0%25B8%2520%25D0%25B4%25D0%25BE%25D0%25BA%25D1%2583%25D0%25BC%25D0%25B5%25D0%25BD%25D1%2582%25D0%25B8%2520%25D0%25B2i%25D0%25B4%252023.09.2024p.url%2522"><i>Платежное Поручение в iнозеной валюте та сопроводiтельни документи вiд 23.09.2024p.url</i> </a> (2e33c2010f95cbda8bf0817f1b5c69b51c860c536064182b67261f695f54e1d5) points to an attacker-controlled server hosting another ZIP archive.</p> </div> </div> <div class="image"> </div> <div class="image"> <figure class="image-figure"> <a class="bs-modal" id="b5513e" data-modal-title="Figure 11. File properties of Платежное Поручение в iнозеной валюте та сопроводiтельни документи вiд 23.09.2024p.url" href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig11.png"> <img src="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig11.png" alt="Figure 11. File properties of Платежное Поручение в iнозеной валюте та сопроводiтельни документи вiд 23.09.2024p.url"/> </a> <div class="caption-image-container "> <figcaption>Figure 11. File properties of Платежное Поручение в iнозеной валюте та сопроводiтельни документи вiд 23.09.2024p.url</figcaption> <div class="download-anchor-wrapper"> <a href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig11.png" class="download-anchor" download> <span class="material-symbols-outlined">download</span> </a> </div> </div> </figure> </div> <div class="richText"> <div> <p>As we can see in Figure 11, the file icon of <a href="https://www.virustotal.com/gui/search/name%253A%2522%25D0%259F%25D0%25BB%25D0%25B0%25D1%2582%25D0%25B5%25D0%25B6%25D0%25BD%25D0%25BE%25D0%25B5%2520%25D0%259F%25D0%25BE%25D1%2580%25D1%2583%25D1%2587%25D0%25B5%25D0%25BD%25D0%25B8%25D0%25B5%2520%25D0%25B2%2520i%25D0%25BD%25D0%25BE%25D0%25B7%25D0%25B5%25D0%25BD%25D0%25BE%25D0%25B9%2520%25D0%25B2%25D0%25B0%25D0%25BB%25D1%258E%25D1%2582%25D0%25B5%2520%25D1%2582%25D0%25B0%2520%25D1%2581%25D0%25BE%25D0%25BF%25D1%2580%25D0%25BE%25D0%25B2%25D0%25BE%25D0%25B4i%25D1%2582%25D0%25B5%25D0%25BB%25D1%258C%25D0%25BD%25D0%25B8%2520%25D0%25B4%25D0%25BE%25D0%25BA%25D1%2583%25D0%25BC%25D0%25B5%25D0%25BD%25D1%2582%25D0%25B8%2520%25D0%25B2i%25D0%25B4%252023.09.2024p.url%2522"><i>Платежное Поручение в iнозеной валюте та сопроводiтельни документи вiд 23.09.2024p.url</i></a> is spoofed to display a ZIP archive icon designed to further trick the user into executing the file. This file does not contain MoTW protections due to the exploitation of CVE-2025-0411.</p> <h2><span class="body-subhead-title"><span class="rte-sub-menu-text">In-the-wild: contents of invoice.zip</span></span></h2> <p>The archive file <a href="https://www.virustotal.com/gui/search/name%253Ainvoce.zip"><i>invoce.zip</i></a> (888f68917f9250a0936fd66ea46b6c510d0f6a0ca351ee62774dd14268fe5420) contains an executable <a href="https://www.virustotal.com/gui/file/a059d671d950abee93ef78a170d58a3839c2a465914ab3bd5411e39c89ae55a2/details"><i>Платежное Поручение в iнозеной валюте.pdf.exe</i></a> (a059d671d950abee93ef78a170d58a3839c2a465914ab3bd5411e39c89ae55a2) disguised as a PDF document.</p> </div> </div> <div class="image"> <figure class="image-figure"> <a class="bs-modal" id="3e57fc" data-modal-title="Figure 12. File properties of Платежное Поручение в iнозеной валюте.pdf.exe" href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig12.png"> <img src="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig12.png" alt="Figure 12. File properties of Платежное Поручение в iнозеной валюте.pdf.exe"/> </a> <div class="caption-image-container "> <figcaption>Figure 12. File properties of Платежное Поручение в iнозеной валюте.pdf.exe</figcaption> <div class="download-anchor-wrapper"> <a href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/fig12.png" class="download-anchor" download> <span class="material-symbols-outlined">download</span> </a> </div> </div> </figure> </div> <div class="richText"> <div> <p>Once <a href="https://www.virustotal.com/gui/file/a059d671d950abee93ef78a170d58a3839c2a465914ab3bd5411e39c89ae55a2/details"><i>Платежное Поручение в iнозеной валюте.pdf.exe</i></a> is executed, the SmokeLoader payload is also then executed, leading to malware infection and full system compromise.</p> <h1><span class="body-subhead-title">Known Ukrainian organizations affected or targeted by the zero-day exploit</span></h1> <p>Based on the data we’ve uncovered, the following Ukrainian government entities and other organizations may have been directly targeted and/or affected by this campaign:</p> <ul> <li><span class="rte-red-bullet"><a href="https://uk.wikipedia.org/wiki/%D0%94%D0%B5%D1%80%D0%B6%D0%B0%D0%B2%D0%BD%D0%B0_%D0%B2%D0%B8%D0%BA%D0%BE%D0%BD%D0%B0%D0%B2%D1%87%D0%B0_%D1%81%D0%BB%D1%83%D0%B6%D0%B1%D0%B0_%D0%A3%D0%BA%D1%80%D0%B0%D1%97%D0%BD%D0%B8">State Executive Service of Ukraine (SES)</a> – Ministry of Justice</span></li> <li><span class="rte-red-bullet"><a href="https://zaporizhzhia.city/en/places/zaporozhskiy-avtomobilestroitelnyy-zavod">Zaporizhzhia Automobile Building Plant (PrJSC ZAZ)</a> – Automobile, bus, and truck manufacturer</span></li> <li><span class="rte-red-bullet"><a href="https://kpt.kyiv.ua/">Kyivpastrans</a> – Kyiv Public Transportation Service</span></li> <li><span class="rte-red-bullet"><a href="https://www.sea.com.ua/en/">SEA Company</a> – Appliances, electrical equipment, and electronics manufacturer</span></li> <li><span class="rte-red-bullet"><a href="https://verhovuna-rda.gov.ua/">Verkhovyna District State Administration</a> - Ivano-Frankivsk oblast administration</span></li> <li><span class="rte-red-bullet"><a href="https://vuso.ua/en/about">VUSA</a> – Insurance company</span></li> <li><span class="rte-red-bullet"><a href="https://opendatabot.ua/c/01976358">Dnipro City Regional Pharmacy</a> – Regional pharmacy</span></li> <li><span class="rte-red-bullet"><a href="https://vodokanal.kiev.ua/">Kyivvodokanal</a> – Kyiv Water Supply Company</span></li> <li><span class="rte-red-bullet"><a href="http://zalrada.gov.ua/">Zalishchyky City Council</a> – City council</span></li> </ul> <p>Note that this compilation of organizations impacted by the CVE-2025-0411 zero-day attack is not comprehensive; there is a significant likelihood that additional organizations may have been affected or targeted by the perpetrators.</p> <p>It appears that some of the compromised email accounts may have been acquired from prior campaigns, and it is possible that newly compromised accounts will be incorporated into future operations. The use of these compromised email accounts lend an air of authenticity to the emails sent to targets, manipulating potential victims into trusting the content and their senders.</p> <p>One interesting takeaway we noticed in the organizations targeted and affected in this campaign is smaller local government bodies. These organizations are often under intense cyber pressure yet are often overlooked, less cyber-savvy, and lack the resources for a comprehensive cyber strategy that larger government organizations have. These smaller organizations can be valuable pivot points by threat actors to pivot to larger government organizations.</p> <h1><span class="body-subhead-title">Recommendations</span></h1> <p>To minimize the risks associated with CVE-2025-0411 and similar vulnerabilities, we recommend that organizations adhere to the following best practices:</p> <ul> <li><span class="rte-red-bullet">Ensure that all instances of 7-Zip are updated to version 24.09 or later. This version addresses the CVE-2025-0411 vulnerability.</span></li> <li><span class="rte-red-bullet">Implement strict email security measures, including the use of email filtering and anti-spam technologies to detect and block spear-phishing attacks.</span></li> <li><span class="rte-red-bullet">Train employees to recognize and report phishing attempts. Regularly update them on the latest phishing tactics, including homoglyph attacks on files and filetypes, as discussed in this entry.</span></li> <li><span class="rte-red-bullet">Educate users on zero-day and n-day vulnerabilities and their role in preventing their exploitation.</span></li> <li><span class="rte-red-bullet">Educate users on the importance of MoTW and its role in preventing the automatic execution of potentially harmful scripts or applications.</span></li> <li><span class="rte-red-bullet">Disable the automatic execution of files from untrusted sources and configure systems to prompt users for verification before opening such files.</span></li> <li><span class="rte-red-bullet">·Implement domain filtering and monitoring to detect and block homoglyph-based phishing attacks.</span></li> <li><span class="rte-red-bullet">Use URL filtering to block access to known malicious domains and regularly update blacklists with newly identified threat domains.<br /> </span></li> </ul> <h1><span class="body-subhead-title">Trend Vision One™</span></h1> <p><a href="/en_hk/business/products/one-platform.html">Trend Vision One™</a> is a cybersecurity platform that simplifies security and helps enterprises detect and stop threats faster by consolidating multiple security capabilities, enabling greater command of the enterprise’s attack surface, and providing complete visibility into its cyber risk posture. The cloud-based platform leverages AI and threat intelligence from 250 million sensors and 16 threat research centers around the globe to provide comprehensive risk insights, earlier threat detection, and automated risk and threat response options in a single solution.</p> <h1><span class="body-subhead-title">Trend Vision One Threat Intelligence</span></h1> <p>To stay ahead of evolving threats, Trend Vision One customers can access a range of Intelligence Reports and Threat Insights within Vision One. Threat Insights helps customers stay ahead of cyber threats before they happen and allows them to prepare for emerging threats by offering comprehensive information on threat actors, their malicious activities, and their techniques. By leveraging this intelligence, customers can take proactive steps to protect their environments, mitigate risks, and effectively respond to threats.</p> <h2><span class="body-subhead-title"><span class="rte-sub-menu-text">Trend Vision One Intelligence Reports App [IOC Sweeping]</span></span></h2> <ul> <li><span class="rte-red-bullet">CVE-2025-0411: Analysis of a Zero-Day Vulnerability and its Use in Cyber Espionage<br /> <br /> </span></li> <li> </li> <li>Trend Vision One Threat Insights App<br /> <br /> <br /> </li> <li><span class="rte-red-bullet"> Emerging Threats: <a href="https://portal.xdr.trendmicro.com/index.html#/app/ti/intelligence_insights?name=CVE-2025-0411:%20Analysis%20of%20a%20Zero-Day%20Vulnerability%20and%20its%20Use%20in%20Cyber%20Espionage">CVE-2025-0411: Analysis of a Zero-Day Vulnerability and its Use in Cyber Espionage</a></span></li> <li> </li> </ul> <h1><span class="body-subhead-title">Hunting Queries</span></h1> <p><span class="body-subhead-title"><span class="rte-sub-menu-text">Trend Vision One Search App</span></span></p> <p>Trend Vision One customers can use the Search App to match or hunt the malicious indicators mentioned in this blog post with data in their environment. </p> <p><b><span class="body-subhead-title"><span class="rte-sub-menu-text">SmokeLoader VSAPI Detections</span></span></b></p> <p><span class="blockquote">malName:*SMOKELOADER* AND eventName:MALWARE_DETECTION AND LogType: detection</span></p> <p>More hunting queries are available for Trend Vision One customers with <a href="/en_hk/business/products/one-platform/threat-insights.html">Threat Insights Entitlement enabled</a>.</p> <h1><span class="body-subhead-title">Conclusion</span></h1> <p>It is important that everyone using 7-Zip update to <a href="https://sourceforge.net/projects/sevenzip/files/7-Zip/24.09/">7-Zip version 24.09</a> immediately, especially since CVE-2025-0411 has been under active exploitation since at least September 2024, with PoC concepts existing as well.</p> <p>The exploitation of CVE-2025-0411 signifies another instance of a zero-day vulnerability being used in the context of the ongoing cyber front of the Russo-Ukrainian conflict. This situation illustrates the dynamic nature of the current cyber conflict, particularly the employment of advanced zero-day deployment techniques, notably through homoglyph attacks.</p> <p>To the best of our knowledge, this represents the first occasion in which a homoglyph attack has been integrated into a zero-day exploit chain, thereby elevating concerns regarding the progression of such attacks beyond traditional methods such as credential harvesting, phishing, and website spoofing.</p> <p>Furthermore, this campaign highlights the need for organizations to enhance their cybersecurity training programs by incorporating an understanding of homoglyph attacks, especially in relation to files, file extensions, and zero-day exploitation rather than limiting the focus to web spoofing alone. The Trend ZDI Threat Hunting team engages in proactive efforts to identify zero-day exploitation in the wild, therefore safeguarding organizations against real-world threats prior to vendor awareness.</p> <p>We’ll be back with more findings as we have them. Until then, you can follow the Trend ZDI team on <a href="https://www.twitter.com/thezdi">Twitter</a>, <a href="https://infosec.exchange/@thezdi">Mastodon</a>, <a href="https://www.linkedin.com/company/zerodayinitiative">LinkedIn</a>, or <a href="https://bsky.app/profile/thezdi.bsky.social">Bluesky </a>for the latest in exploit techniques and security patches.</p> <p><span class="body-subhead-title">Indicators of Compromise</span></p> <p>The indicators of compromise for this entry can be found <a href="/content/dam/trendmicro/global/en/research/25/a/cve-2025-0411-ukrainian-organizations-targeted-in-zero-day-campaign-and-homoglyph-attacks/ioc-CVE-2025-0411.txt" title="Indicators of Compromise"><span class="bs-modal">here</span></a>.</p> </div> </div> </div> <section class="tag--list"> <div class="tag--list-title">Tags</div> <div class="tag--list-tags"> <a href="/en_hk/research.html?category=trend-micro-research:threats/apt-and-targeted-attacks" class="tag--list-anchor">APT & Targeted Attacks</a> <span class="tag--list-separator" role="separator">|</span> <a href="/en_hk/research.html?category=trend-micro-research:environments/endpoints" class="tag--list-anchor">Endpoints</a> <span class="tag--list-separator" role="separator">|</span> <a href="/en_hk/research.html?category=trend-micro-research:threats/exploits-and-vulnerabilities" class="tag--list-anchor">Exploits & Vulnerabilities</a> <span class="tag--list-separator" role="separator">|</span> <a href="/en_hk/research.html?category=trend-micro-research:article-type/research" class="tag--list-anchor">Research</a> <span class="tag--list-separator" role="separator">|</span> <a href="/en_hk/research.html?category=trend-micro-research:medium/article" class="tag--list-anchor">Articles, News, Reports</a> </div> </section> </main> <sidebar class="sidebar--left col-xs-12 col-lg-2 col-lg-pull-8"> <h3 class="article-authors__title"> Authors </h3> <!-- /* Show Trend Micro if we don't have any authors for this article */ --> <ul class="article-authors__list"> <li class="article-authors__list-items"> <div class="article-authors__wrapper" role="contentinfo authors profile"> <p class="article-authors__list-items__name">Peter Girnus</p> <p class="article-authors__list-items__position">Sr. Threat Researcher</p> </div> </li> </ul> <div class="article-authors__btn-wrapper" role="button"> <a class="article-authors__button " href="mailto:tm_research@trendmicro.com" target="target" id="article-authors-contact-us-button"> Contact Us </a> </div> </sidebar> <sidebar class="sidebar--right col-xs-12 col-lg-2"> <div class="sidebar--wrapper" role="contentinfo sidebar"> <div class="row-1" role="contentinfo related articles"> <div class="related--articles" role="contentinfo related articles"> <h3 class="related--articles-title">Related Articles</h3> <ul class="related--articles-items"> <li class="related--articles-item"> <a class="related--articles-item-anchor" href="/en_hk/research/25/b/updated-shadowpad-malware-leads-to-ransomware-deployment.html"> Updated Shadowpad Malware Leads to Ransomware Deployment </a> </li> <li class="related--articles-item"> <a class="related--articles-item-anchor" href="/en_hk/research/25/b/earth-preta-mixes-legitimate-and-malicious-components-to-sidestep-detection.html"> Earth Preta Mixes Legitimate and Malicious Components to Sidestep Detection </a> </li> <li class="related--articles-item"> <a class="related--articles-item-anchor" href="/en_hk/research/23/k/zero-day-threat-protection.html"> Zero Day Threat Protection for Your Network </a> </li> </ul> </div> <div class="archived--link"> <div class="archived--link-text"> <a href="/en_hk/research.html"> See all articles </a> </div> <div class="archived--link-icon"> <a href="/en_hk/research.html"> <span class="icon-chevron-right"></span> </a> </div> </div> </div> </div> </sidebar> </article> </div></div> </div> </div> <div class="footer"> <div class="containerV1"><div class="footer_wrapper footer-wrapper"><div class="containerV1"> <div class="container-content"> <div class="gridContainerV1 section"> <style> /* MOBILE (Default) */ #grid-areas-bba97b30-20ee-47e0-8ac4-cf21e2f59a3b { display: grid; gap: 10px 0px; grid-template-columns: 1fr; } #grid-areas-bba97b30-20ee-47e0-8ac4-cf21e2f59a3b .hideOnMobile { display: none; } /* TABLET ($tablet-up: 768px) */ @media ( max-width: 1023px ) and ( min-width: 768px ) { #grid-areas-bba97b30-20ee-47e0-8ac4-cf21e2f59a3b { gap: 10px 0px; grid-template-columns: 1fr; } #grid-areas-bba97b30-20ee-47e0-8ac4-cf21e2f59a3b .hideOnMobile { display: block; } #grid-areas-bba97b30-20ee-47e0-8ac4-cf21e2f59a3b .hideOnTablet { display: none; } } /* WIDE TABLET ($desktop-up: 1024px) */ @media ( max-width: 1199px ) and ( min-width: 1024px ) { #grid-areas-bba97b30-20ee-47e0-8ac4-cf21e2f59a3b { gap: 0px 10px; grid-template-columns: 6fr 6fr 6fr 6fr; } #grid-areas-bba97b30-20ee-47e0-8ac4-cf21e2f59a3b .hideOnMobile { display: block; } #grid-areas-bba97b30-20ee-47e0-8ac4-cf21e2f59a3b .hideOnWideTablet { display: none; } } /* DESKTOP ($desktop-large-up: 1200px) */ @media ( max-width: 1599px ) and ( min-width: 1200px ) { #grid-areas-bba97b30-20ee-47e0-8ac4-cf21e2f59a3b { gap: 0px 10px; grid-template-columns: 3fr 3fr 3fr 3fr; } #grid-areas-bba97b30-20ee-47e0-8ac4-cf21e2f59a3b .hideOnMobile { display: block; } #grid-areas-bba97b30-20ee-47e0-8ac4-cf21e2f59a3b .hideOnDesktop { display: none; } } /* WIDE DESKTOP ($desktop-xl-up: 1600px) */ @media ( min-width: 1600px ) { #grid-areas-bba97b30-20ee-47e0-8ac4-cf21e2f59a3b { gap: 0px 10px; grid-template-columns: 3fr 3fr 3fr 4fr; } #grid-areas-bba97b30-20ee-47e0-8ac4-cf21e2f59a3b .hideOnMobile { display: block; } #grid-areas-bba97b30-20ee-47e0-8ac4-cf21e2f59a3b .hideOnWideDesktop { display: none; } } </style> <div class="gridAreas global-margin-top-none global-margin-bottom-none global-padding-top-none global-padding-bottom-none" id="grid-areas-bba97b30-20ee-47e0-8ac4-cf21e2f59a3b"> <div class="grid-resources-tab1 "><div class="footer section"> <div class="footerMenu"> <h3>Resources</h3> <ul> <li><a href="/en_hk/research.html" target="_self" rel="noopener noreferrer">Blog</a></li> <li><a href="/en_hk/about/newsroom.html" target="_self" rel="noopener noreferrer">Newsroom</a></li> <li><a href="https://www.trendmicro.com/vinfo/us/security/research-and-analysis/threat-reports" target="_self" rel="noopener noreferrer">Threat Reports</a></li> <li><a href="https://partner.trendmicro.com/partner-locator-home/" target="_blank" rel="noopener noreferrer">Find a Partner</a></li> <li><a target="_self" rel="noopener noreferrer"></a></li> <li><a target="_self" rel="noopener noreferrer"></a></li> </ul> </div> </div> </div> <div class="grid-support-tab1 "><div class="footer section"> <div class="footerMenu"> <h3>Support</h3> <ul> <li><a href="https://success.trendmicro.com/en-US/" target="_blank" rel="noopener noreferrer">Business Support Portal</a></li> <li><a href="/en_hk/business/get-info-form.html" target="_self" rel="noopener noreferrer">Contact Us</a></li> <li><a href="/en_hk/business/products/downloads.html" target="_self" rel="noopener noreferrer">Downloads</a></li> <li><a href="/en_hk/business/products/trials.html" target="_self" rel="noopener noreferrer">Free Trials</a></li> <li><a target="_self" rel="noopener noreferrer"></a></li> <li><a target="_self" rel="noopener noreferrer"></a></li> </ul> </div> </div> </div> <div class="grid-about-tab1 "><div class="footer section"> <div class="footerMenu"> <h3>About Trend</h3> <ul> <li><a href="/en_hk/about.html" target="_self" rel="noopener noreferrer">About Us</a></li> <li><a href="/en_hk/about/careers.html" target="_self" rel="noopener noreferrer">Careers</a></li> <li><a href="/en_hk/contact.html" target="_self" rel="noopener noreferrer">Locations</a></li> <li><a href="/en_hk/about/events.html" target="_self" rel="noopener noreferrer">Upcoming Events</a></li> <li><a href="/en_hk/about/trust-center.html" target="_self" rel="noopener noreferrer">Trust Center</a></li> <li><a target="_self" rel="noopener noreferrer"></a></li> </ul> </div> </div> </div> <div class="grid-address-tab1 "><div class="reference parbase section"><div class="cq-dd-paragraph"><div class="footer"> <script type="application/ld+json"> {"@context":"https://schema.org","@type":"Organization","name":"Trend Micro - Hong Kong (HK)","telephone":"+852-2214-3200","address":{"addressLocality":"Wanchai","addressRegion":"Hong Kong","postalCode":"","streetAddress":"903-905 9/F Shui On Centre 6-8 Harbour Road"}} </script> <div class="organization footerMenu footer-address-menu"> <h3 class="title">Country Headquarters</h3> <ul class="footer-address-wrapper"> <li class="name">Trend Micro - Hong Kong (HK)</li> <li class="address"> 903-905 9/F Shui On Centre<br/> 6-8 Harbour Road Wanchai </li> <li class="phone">Phone:: +852-2214-3200</li> </ul> </div> </div> </div> </div> </div> </div> </div> <div class="horizontalSeparatorV1 section"> <style> .horizontalSeparator-baf26787-1e65-45ef-a4e7-b8659d035533.border { border-bottom: 1px solid #bcbdc0; } </style> <div id="horizontalV1-baf26787-1e65-45ef-a4e7-b8659d035533" class="global-margin-top- global-margin-bottom-medium global-padding-top-small global-padding-bottom- border horizontalSeparator-baf26787-1e65-45ef-a4e7-b8659d035533"> </div> </div> <div class="gridContainerV1 section"> <style> /* MOBILE (Default) */ #grid-areas-7a35191c-5804-4465-84de-dfff811952d8 { display: grid; gap: 0px 0px; grid-template-columns: 1fr; } #grid-areas-7a35191c-5804-4465-84de-dfff811952d8 .hideOnMobile { display: none; } /* TABLET ($tablet-up: 768px) */ @media ( max-width: 1023px ) and ( min-width: 768px ) { #grid-areas-7a35191c-5804-4465-84de-dfff811952d8 { gap: 0px 0px; grid-template-columns: 1fr; } #grid-areas-7a35191c-5804-4465-84de-dfff811952d8 .hideOnMobile { display: block; } #grid-areas-7a35191c-5804-4465-84de-dfff811952d8 .hideOnTablet { display: none; } } /* WIDE TABLET ($desktop-up: 1024px) */ @media ( max-width: 1199px ) and ( min-width: 1024px ) { #grid-areas-7a35191c-5804-4465-84de-dfff811952d8 { gap: 0px 0px; grid-template-columns: 3fr 3fr 6fr; } #grid-areas-7a35191c-5804-4465-84de-dfff811952d8 .hideOnMobile { display: block; } #grid-areas-7a35191c-5804-4465-84de-dfff811952d8 .hideOnWideTablet { display: none; } } /* DESKTOP ($desktop-large-up: 1200px) */ @media ( max-width: 1599px ) and ( min-width: 1200px ) { #grid-areas-7a35191c-5804-4465-84de-dfff811952d8 { gap: 0px 0px; grid-template-columns: 1fr 2fr 2fr; } #grid-areas-7a35191c-5804-4465-84de-dfff811952d8 .hideOnMobile { display: block; } #grid-areas-7a35191c-5804-4465-84de-dfff811952d8 .hideOnDesktop { display: none; } } /* WIDE DESKTOP ($desktop-xl-up: 1600px) */ @media ( min-width: 1600px ) { #grid-areas-7a35191c-5804-4465-84de-dfff811952d8 { gap: 0px 0px; grid-template-columns: 1fr 2fr 2fr; } #grid-areas-7a35191c-5804-4465-84de-dfff811952d8 .hideOnMobile { display: block; } #grid-areas-7a35191c-5804-4465-84de-dfff811952d8 .hideOnWideDesktop { display: none; } } </style> <div class="gridAreas global-margin-top-none global-margin-bottom-none global-padding-top-none global-padding-bottom-none" id="grid-areas-7a35191c-5804-4465-84de-dfff811952d8"> <div class="grid-footer-locale1 "><div class="footer section"> <ul class="social-media-links"> <li> <a href="https://www.linkedin.com/company/trend-micro/" class="social-icon linkedin" target="_blank" rel="noopener noreferrer"> <svg xmlns="http://www.w3.org/2000/svg" width="18" height="18" viewBox="0 0 18 18"> <path id="LinkedIn" d="M8.8,10.3a1.5,1.5,0,0,1,1.5-1.5H25.295A1.5,1.5,0,0,1,26.8,10.3V25.294A1.5,1.5,0,0,1,25.3,26.8H10.3a1.5,1.5,0,0,1-1.5-1.5Zm7.125,5.359h2.437v1.224a2.793,2.793,0,0,1,2.6-1.337c2.593,0,3.207,1.4,3.207,3.973v4.763H21.55V20.109c0-1.465-.352-2.291-1.245-2.291-1.24,0-1.755.891-1.755,2.291v4.178H15.925Zm-4.5,8.512H14.05V15.55H11.425v8.624Zm3-11.437a1.688,1.688,0,1,1-.507-1.17A1.689,1.689,0,0,1,14.425,12.737Z" transform="translate(-8.8 -8.8)" fill="#020607" fill-rule="evenodd"/> </svg> </a> </li> <li> <a href="https://www.facebook.com/TrendMicro/" class="social-icon facebook" target="_blank" rel="noopener noreferrer"> <svg xmlns="http://www.w3.org/2000/svg" width="18" height="18" viewBox="0 0 18 18"> <path id="Facebook" d="M56.087,8.8A3.28,3.28,0,0,0,52.8,12.087V23.513A3.28,3.28,0,0,0,56.087,26.8H62.28V19.763H60.419V17.229H62.28V15.065c0-1.7,1.1-3.262,3.632-3.262a15.371,15.371,0,0,1,1.784.1l-.06,2.366s-.773-.007-1.617-.007c-.913,0-1.06.421-1.06,1.119v1.85h2.75l-.12,2.533h-2.63V26.8h2.554A3.28,3.28,0,0,0,70.8,23.513V12.087A3.28,3.28,0,0,0,67.513,8.8H56.087Z" transform="translate(-52.8 -8.8)" fill="#020607"/> </svg> </a> </li> <li> <a href="https://x.com/trendmicro" class="social-icon twitter" target="_blank" rel="noopener noreferrer"> <!--NEW X LOGO--> <svg xmlns="http://www.w3.org/2000/svg" width="19.57" height="20" viewBox="0 0 19.57 20"> <path id="x-logo" d="M11.647,8.469,18.932,0H17.206L10.88,7.353,5.827,0H0L7.64,11.119,0,20H1.726l6.68-7.765L13.743,20H19.57L11.646,8.469ZM9.282,11.217,8.508,10.11,2.349,1.3H5L9.971,8.41l.774,1.107,6.461,9.242H14.555L9.282,11.218Z"/> </svg> <!--OLD BIRD LOGO--> <!-- <svg xmlns="http://www.w3.org/2000/svg" width="20" height="16" viewBox="0 0 20 16">--> <!-- <path id="Twitter" d="M116,11.5a8.307,8.307,0,0,1-2.356.635,4.055,4.055,0,0,0,1.8-2.235,8.271,8.271,0,0,1-2.6.979,4.154,4.154,0,0,0-4.934-.8,4.064,4.064,0,0,0-1.8,1.9,3.981,3.981,0,0,0-.256,2.586,11.806,11.806,0,0,1-4.685-1.225,11.625,11.625,0,0,1-3.772-2.995,3.991,3.991,0,0,0-.071,3.936,4.063,4.063,0,0,0,1.341,1.456,4.142,4.142,0,0,1-1.858-.505v.052a4,4,0,0,0,.928,2.558,4.117,4.117,0,0,0,2.364,1.4,4.2,4.2,0,0,1-1.853.069,4.042,4.042,0,0,0,1.46,2.007,4.15,4.15,0,0,0,2.374.8,8.321,8.321,0,0,1-5.1,1.729A8.491,8.491,0,0,1,96,23.785a11.741,11.741,0,0,0,6.289,1.814,11.5,11.5,0,0,0,11.676-11.489c0-.173-.005-.349-.012-.522A8.284,8.284,0,0,0,116,11.5Z" transform="translate(-96 -9.6)" fill="#020607"></path>--> <!-- </svg>--> </a> </li> <li> <a href="https://www.instagram.com/trendmicro/" class="social-icon instagram" target="_blank" rel="noopener noreferrer"> <svg xmlns="http://www.w3.org/2000/svg" width="18" height="18" viewBox="0 0 18 18"> <path id="Instagram" d="M146.09,8.854c.959-.044,1.265-.054,3.71-.054s2.751.011,3.71.054a6.631,6.631,0,0,1,2.186.418,4.607,4.607,0,0,1,2.631,2.632,6.641,6.641,0,0,1,.419,2.184c.044.961.054,1.267.054,3.711s-.011,2.751-.054,3.711a6.61,6.61,0,0,1-.419,2.184,4.6,4.6,0,0,1-2.631,2.632,6.626,6.626,0,0,1-2.185.419c-.96.044-1.266.054-3.711.054s-2.751-.011-3.71-.054a6.6,6.6,0,0,1-2.185-.419,4.595,4.595,0,0,1-2.633-2.631,6.643,6.643,0,0,1-.419-2.185c-.044-.961-.054-1.267-.054-3.711s.01-2.751.054-3.71a6.611,6.611,0,0,1,.419-2.186A4.611,4.611,0,0,1,143.9,9.272a6.65,6.65,0,0,1,2.185-.418Zm7.346,1.62c-.949-.043-1.234-.052-3.636-.052s-2.687.009-3.636.052a4.976,4.976,0,0,0-1.673.31,2.972,2.972,0,0,0-1.708,1.708,4.968,4.968,0,0,0-.31,1.671c-.044.949-.053,1.234-.053,3.637s.009,2.688.053,3.637a4.968,4.968,0,0,0,.31,1.671,2.972,2.972,0,0,0,1.708,1.708,4.976,4.976,0,0,0,1.673.31c.949.043,1.232.052,3.636.052s2.688-.009,3.636-.052a4.976,4.976,0,0,0,1.673-.31,2.972,2.972,0,0,0,1.708-1.708,4.968,4.968,0,0,0,.31-1.671c.043-.949.053-1.234.053-3.637s-.01-2.688-.053-3.637a4.968,4.968,0,0,0-.31-1.671,2.972,2.972,0,0,0-1.708-1.708A4.976,4.976,0,0,0,153.436,10.474Zm-4.786,10.1a3,3,0,1,0-1.075-.758A3,3,0,0,0,148.65,20.574Zm-2.121-6.046a4.626,4.626,0,1,1-1.355,3.271A4.634,4.634,0,0,1,146.529,14.529Zm8.924-.666a1.091,1.091,0,0,0,.25-.355,1.1,1.1,0,0,0,.093-.425,1.093,1.093,0,1,0-.343.78Z" transform="translate(-140.8 -8.8)" fill="#020607" fill-rule="evenodd"/> </svg> </a> </li> <li> <a href="https://www.youtube.com/user/TrendMicroInc" class="social-icon youtube" target="_blank" rel="noopener noreferrer"> <svg xmlns="http://www.w3.org/2000/svg" width="24.003" height="16.01" viewBox="0 0 24.003 16.01"> <path id="YouTube" d="M205.9,12.112a2.78,2.78,0,0,0-.765-1.27A3.052,3.052,0,0,0,203.8,10.1c-1.877-.495-9.4-.495-9.4-.495a76.616,76.616,0,0,0-9.39.47,3.156,3.156,0,0,0-1.339.76,2.9,2.9,0,0,0-.777,1.276A29.133,29.133,0,0,0,182.4,17.6a29.058,29.058,0,0,0,.489,5.494,2.818,2.818,0,0,0,.775,1.269,3.094,3.094,0,0,0,1.341.743c1.9.494,9.39.494,9.39.494a76.8,76.8,0,0,0,9.4-.47,3.051,3.051,0,0,0,1.339-.742,2.785,2.785,0,0,0,.765-1.27,28.339,28.339,0,0,0,.5-5.495,26.534,26.534,0,0,0-.5-5.517ZM192,21.029V14.182l6.26,3.424Z" transform="translate(-182.4 -9.6)" fill="#020607"/> </svg> </a> </li> </ul> </div> <div class="footer section"> <div class="country-selection"> <p>Select a country / region</p> <div class="dropup position-unset"> <button class="btn btn-default dropdown-toggle" type="button" id="countryMenu" data-toggle="dropdown" aria-haspopup="true" aria-expanded="false"> <span class="stateSelect"></span> <span class="material-symbols-outlined"> expand_more</span> </button> <div class="row dropdown-menu" aria-labelledby="countryMenu"> <span class="material-symbols-outlined icon-close">close</span> <div class="coloumn col-xs-12 col-sm-6 col-md-2"> <h4>The Americas</h4> <ul> <li> <a href="/en_us.html">United States</a> </li> <li> <a href="/pt_br.html">Brasil</a> </li> <li> <a href="/en_ca.html">Canada</a> </li> <li> <a href="/es_mx.html">México</a> </li> </ul> </div> <div class="coloumn col-xs-12 col-sm-6 col-md-2"> <h4>Middle East & Africa</h4> <ul> <li> <a href="/en_za.html">South Africa</a> </li> <li> <a href="/en_ae.html">Middle East and North Africa</a> </li> </ul> </div> <div class="coloumn col-xs-12 col-sm-6 col-md-4"> <h4>Europe</h4> <ul> <li> <a href="/en_be.html">België (Belgium)</a> </li> <li> <a href="http://www.trendmicro.cz/">Česká Republika</a> </li> <li> <a href="/en_dk.html">Danmark</a> </li> <li> <a href="/de_de.html">Deutschland, Österreich Schweiz</a> </li> <li> <a href="/es_es.html">España</a> </li> <li> <a href="/fr_fr.html">France</a> </li> <li> <a href="/en_ie.html">Ireland</a> </li> <li> <a href="/it_it.html">Italia</a> </li> <li> <a href="/en_nl.html">Nederland</a> </li> <li> <a href="/en_no.html">Norge (Norway)</a> </li> <li> <a href="/pl_pl.html">Polska (Poland)</a> </li> <li> <a href="/en_fi.html">Suomi (Finland)</a> </li> <li> <a href="/en_se.html">Sverige (Sweden)</a> </li> <li> <a href="/tr_tr.html">Türkiye (Turkey)</a> </li> <li> <a href="/en_gb.html">United Kingdom</a> </li> </ul> </div> <div class="coloumn col-xs-12 col-sm-6 col-md-4"> <h4>Asia & Pacific</h4> <ul> <li> <a href="/en_au.html">Australia</a> </li> <li> <a href="/ru_ru.html">Центральная Азия (Central Asia)</a> </li> <li> <a href="/en_hk.html">Hong Kong (English)</a> </li> <li> <a href="/zh_hk.html">香港 (中文) (Hong Kong) </a> </li> <li> <a href="/en_in.html">भारत गणराज्य (India)</a> </li> <li> <a href="/in_id.html">Indonesia</a> </li> <li> <a href="/ja_jp.html">日本 (Japan)</a> </li> <li> <a href="/ko_kr/business.html">대한민국 (South Korea)</a> </li> <li> <a href="/en_my.html">Malaysia</a> </li> <li> <a href="/en_us.html">Монголия (Mongolia) and рузия (Georgia)</a> </li> <li> <a href="/en_nz.html">New Zealand</a> </li> <li> <a href="/en_ph.html">Philippines</a> </li> <li> <a href="/en_sg.html">Singapore</a> </li> <li> <a href="/zh_tw.html">台灣 (Taiwan)</a> </li> <li> <a href="/th_th.html"> ประเทศไทย (Thailand)</a> </li> <li> <a href="/vi_vn.html">Việt Nam</a> </li> </ul> </div> </div> </div> </div> </div> </div> <div class="grid-footer-spacer1 hideOnTablet hideOnMobile"> </div> <div class="grid-footer-callout "><div class="footer section"> <div class="createAccount"> <div class="containerV1 section"> <style> @media ( min-width: 1024px ){ #containere173092f-e0d5-4d8a-8876-66e7c048dcf1, .containere173092f-e0d5-4d8a-8876-66e7c048dcf1 { height: auto; background-repeat: no-repeat; background-size: cover; } } @media ( max-width: 1023px ) and ( min-width: 768px ){ #containere173092f-e0d5-4d8a-8876-66e7c048dcf1, .containere173092f-e0d5-4d8a-8876-66e7c048dcf1 { height: auto; background-repeat: no-repeat; background-size: cover; } } @media ( max-width: 767px ){ #containere173092f-e0d5-4d8a-8876-66e7c048dcf1, .containere173092f-e0d5-4d8a-8876-66e7c048dcf1 { height: auto; background-repeat: no-repeat; background-size: cover; } } </style> <div id="containere173092f-e0d5-4d8a-8876-66e7c048dcf1" class="containere173092f-e0d5-4d8a-8876-66e7c048dcf1 container-wrap gray-border global-margin-top-none global-margin-bottom-large global-padding-top-none global-padding-bottom-none rounded-corners-all-20 inner-container-width"> <section> <div class="container-content"> <div class="prod-content"><div class="gridContainerV1 section"> <style> /* MOBILE (Default) */ #grid-areas-3ecb6058-f9cb-4ce5-b274-39ea96af9477 { display: grid; gap: 0px 0px; grid-template-columns: 1fr; } #grid-areas-3ecb6058-f9cb-4ce5-b274-39ea96af9477 .hideOnMobile { display: none; } /* TABLET ($tablet-up: 768px) */ @media ( max-width: 1023px ) and ( min-width: 768px ) { #grid-areas-3ecb6058-f9cb-4ce5-b274-39ea96af9477 { gap: 0px 0px; grid-template-columns: 1fr; } #grid-areas-3ecb6058-f9cb-4ce5-b274-39ea96af9477 .hideOnMobile { display: block; } #grid-areas-3ecb6058-f9cb-4ce5-b274-39ea96af9477 .hideOnTablet { display: none; } } /* WIDE TABLET ($desktop-up: 1024px) */ @media ( max-width: 1199px ) and ( min-width: 1024px ) { #grid-areas-3ecb6058-f9cb-4ce5-b274-39ea96af9477 { gap: 0px 0px; grid-template-columns: 1fr; } #grid-areas-3ecb6058-f9cb-4ce5-b274-39ea96af9477 .hideOnMobile { display: block; } #grid-areas-3ecb6058-f9cb-4ce5-b274-39ea96af9477 .hideOnWideTablet { display: none; } } /* DESKTOP ($desktop-large-up: 1200px) */ @media ( max-width: 1599px ) and ( min-width: 1200px ) { #grid-areas-3ecb6058-f9cb-4ce5-b274-39ea96af9477 { gap: 0px 0px; grid-template-columns: 1fr; } #grid-areas-3ecb6058-f9cb-4ce5-b274-39ea96af9477 .hideOnMobile { display: block; } #grid-areas-3ecb6058-f9cb-4ce5-b274-39ea96af9477 .hideOnDesktop { display: none; } } /* WIDE DESKTOP ($desktop-xl-up: 1600px) */ @media ( min-width: 1600px ) { #grid-areas-3ecb6058-f9cb-4ce5-b274-39ea96af9477 { gap: 0px 0px; grid-template-columns: 1fr 10fr 1fr; } #grid-areas-3ecb6058-f9cb-4ce5-b274-39ea96af9477 .hideOnMobile { display: block; } #grid-areas-3ecb6058-f9cb-4ce5-b274-39ea96af9477 .hideOnWideDesktop { display: none; } } </style> <div class="gridAreas global-margin-top-none global-margin-bottom-none global-padding-top-none global-padding-bottom-none" id="grid-areas-3ecb6058-f9cb-4ce5-b274-39ea96af9477"> <div class="grid-spacing-footer-lft hideOnDesktop hideOnTablet"> </div> <div class="grid-footer-callout "><div class="text primary-color-white section"> <div id="text-2570c84284" class="cmp-text"> <p>Experience our unified platform for free</p> </div> </div> </div> <div class="grid-spacing-footer-rht hideOnDesktop hideOnTablet"> </div> </div> </div> <div class="buttonArrayV1 section"> <ul class="button-array small center-align global-margin-top-none global-margin-bottom-none global-padding-top-none global-padding-bottom-none"> <li class="button-array-list"> <a class="button primary color-ffffff normal" id="footer-free-trial-73c5d9" href="/en_hk/business/products/trials.html"> Claim your 30-day trial </a> </li> </ul> </div> </div> </div> </section> </div> </div> </div> </div> </div> </div> </div> <div class="gridContainerV1 section"> <style> /* MOBILE (Default) */ #grid-areas-67490b3f-7a63-4832-bcee-008da6f4600c { display: grid; gap: 0px 0px; grid-template-columns: 1fr; } #grid-areas-67490b3f-7a63-4832-bcee-008da6f4600c .hideOnMobile { display: none; } /* TABLET ($tablet-up: 768px) */ @media ( max-width: 1023px ) and ( min-width: 768px ) { #grid-areas-67490b3f-7a63-4832-bcee-008da6f4600c { gap: 0px 0px; grid-template-columns: 1fr; } #grid-areas-67490b3f-7a63-4832-bcee-008da6f4600c .hideOnMobile { display: block; } #grid-areas-67490b3f-7a63-4832-bcee-008da6f4600c .hideOnTablet { display: none; } } /* WIDE TABLET ($desktop-up: 1024px) */ @media ( max-width: 1199px ) and ( min-width: 1024px ) { #grid-areas-67490b3f-7a63-4832-bcee-008da6f4600c { gap: 0px 0px; grid-template-columns: 6fr 6fr; } #grid-areas-67490b3f-7a63-4832-bcee-008da6f4600c .hideOnMobile { display: block; } #grid-areas-67490b3f-7a63-4832-bcee-008da6f4600c .hideOnWideTablet { display: none; } } /* DESKTOP ($desktop-large-up: 1200px) */ @media ( max-width: 1599px ) and ( min-width: 1200px ) { #grid-areas-67490b3f-7a63-4832-bcee-008da6f4600c { gap: 0px 0px; grid-template-columns: 6fr 6fr; } #grid-areas-67490b3f-7a63-4832-bcee-008da6f4600c .hideOnMobile { display: block; } #grid-areas-67490b3f-7a63-4832-bcee-008da6f4600c .hideOnDesktop { display: none; } } /* WIDE DESKTOP ($desktop-xl-up: 1600px) */ @media ( min-width: 1600px ) { #grid-areas-67490b3f-7a63-4832-bcee-008da6f4600c { gap: 0px 0px; grid-template-columns: 6fr 6fr; } #grid-areas-67490b3f-7a63-4832-bcee-008da6f4600c .hideOnMobile { display: block; } #grid-areas-67490b3f-7a63-4832-bcee-008da6f4600c .hideOnWideDesktop { display: none; } } </style> <div class="gridAreas global-margin-top-none global-margin-bottom-none global-padding-top-none global-padding-bottom-none" id="grid-areas-67490b3f-7a63-4832-bcee-008da6f4600c"> <div class="grid-footer-legal0 "><div class="footer section"> <div class="horizontalFooterMenu"> <ul> <li> <a href="/en_hk/about/trust-center/privacy.html">Privacy</a> </li> <li> <a href="/en_hk/about/legal.html">Legal</a> </li> <li> <a href="/en_hk/about/legal/accessibility-policy.html">Accessibility</a> </li> <li> <a href="/en_hk/about/legal/terms-of-use.html">Terms of Use</a> </li> <li> <a href="/en_hk/business/sitemap.html">Sitemap</a> </li> </ul> </div> </div> </div> <div class="grid-footer-copyright "><div class="footer section"> <div class="copyright">Copyright ©2025 Trend Micro Incorporated. All rights reserved.</div> </div> </div> </div> </div> </div> </div> <script src="/etc.clientlibs/clientlibs/granite/jquery.min.js"></script> <script src="/etc.clientlibs/clientlibs/granite/utils.min.js"></script> <script src="/etc.clientlibs/clientlibs/granite/jquery/granite.min.js"></script> <script src="/etc.clientlibs/trendmicro/editableTemplateComponents/content/footer/v1/footer/clientLibs.min.js"></script> </div> </div></div> <!-- /* Core functionality javascripts, absolute URL to leverage Akamai CDN */ --> <script src="https://www.trendmicro.com/content/dam/trendmicro/global/core-library/sly.min.js"></script> <script src="https://www.trendmicro.com/content/dam/trendmicro/global/core-library/jwplayer.js"></script> <script type="text/javascript" src="https://www.youtube.com/iframe_api"></script> <script src="/etc.clientlibs/trendresearch/clientlibs/clientlib-trendresearch.min.js"></script> <script src="/etc.clientlibs/trendmicro/clientlibs/trendmicro-core-2/clientlibs/header-footer.min.js"></script> <!--For Modal-start--> <div class="modal-wrap"></div> <div class="jwPlayerString hidden"> <span>sXpIBdPeKzI9PC2p0SWMpUSM2NSxWzPyXTMLlbXmYa0R20xk</span> </div> <!--For Modal-end--> </body> </html>