logo

Russian hackers attacking European maritime and transport orgs using Microsoft Office exploit

ID: 4f63b5e6-9a78-5253-8e9c-413997d5d054

STIX ID: report--4f63b5e6-9a78-5253-8e9c-413997d5d054

Feed Name: The Record from Recorded Future News

Threat Score
88/100

Date Published: 2026-02-05

Date Updated: 2026-05-01

...
...

Researchers report that APT28 (Fancy Bear) conducted a concentrated 72-hour spearphishing campaign exploiting Microsoft Office vulnerability CVE-2026-21509 to target government, maritime, transportation and diplomatic entities across Eastern Europe and beyond. Malicious Office documents deployed MiniDoor (email theft), PixyNetLoader, and ultimately a Covenant backdoor, using compromised government email accounts and legitimate cloud storage (Filen) for command-and-control to blend malicious traffic with normal activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.