Russian hackers attacking European maritime and transport orgs using Microsoft Office exploit
ID: 4f63b5e6-9a78-5253-8e9c-413997d5d054
STIX ID: report--4f63b5e6-9a78-5253-8e9c-413997d5d054
Feed Name: The Record from Recorded Future News
Researchers report that APT28 (Fancy Bear) conducted a concentrated 72-hour spearphishing campaign exploiting Microsoft Office vulnerability CVE-2026-21509 to target government, maritime, transportation and diplomatic entities across Eastern Europe and beyond. Malicious Office documents deployed MiniDoor (email theft), PixyNetLoader, and ultimately a Covenant backdoor, using compromised government email accounts and legitimate cloud storage (Filen) for command-and-control to blend malicious traffic with normal activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
