Hackers Exploiting Microsoft Office 0-day Vulnerability to Deploy Malware
ID: 6aa79af1-a73b-5717-a878-b500f628e11f
STIX ID: report--6aa79af1-a73b-5717-a878-b500f628e11f
Feed Name: cybersecurityNews.com
The report describes active exploitation of Microsoft Office zero-day CVE-2026-21509 by Russia-linked group UAC-0001 (APT28), which weaponized malicious Office documents and a phishing campaign to deliver the COVENANT post-exploitation framework. The attack uses WebDAV to fetch a shortcut with executable code, deploys components like EhStoreShell.dll and shellcode in SplashScreen.png, employs COM hijacking and a persistent scheduled task named 'OneDriveHealth', and leverages Filen cloud storage for C2; CERT-UA warns of rapid exploitation and provides mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
