logo

Russian state hackers exploit new Microsoft Office flaw in attacks on Ukraine, EU

ID: 7cc20bc3-0821-5a3d-9714-b26c30b05057

STIX ID: report--7cc20bc3-0821-5a3d-9714-b26c30b05057

Feed Name: The Record from Recorded Future News

Threat Score
90/100

Date Published: 2026-02-03

Date Updated: 2026-05-01

...
...

Researchers and CERT-UA attribute active exploitation of Microsoft Office vulnerability CVE-2026-21509 to APT28 (Fancy Bear), where malicious Office documents delivered loaders and backdoors (PixyNetLoader, MiniDoor, Covenant) to targets in Ukraine, Slovakia, Romania and other European government entities; Microsoft has released a patch and the vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.