logo

Hackers Exploiting Microsoft Office 0-day Vulnerability to Deploy Malware

ID: 6aa79af1-a73b-5717-a878-b500f628e11f

STIX ID: report--6aa79af1-a73b-5717-a878-b500f628e11f

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-02-02

Date Updated: 2026-04-21

Author: Abinaya

...
...

The report describes active exploitation of Microsoft Office zero-day CVE-2026-21509 by Russia-linked group UAC-0001 (APT28), which weaponized malicious Office documents and a phishing campaign to deliver the COVENANT post-exploitation framework. The attack uses WebDAV to fetch a shortcut with executable code, deploys components like EhStoreShell.dll and shellcode in SplashScreen.png, employs COM hijacking and a persistent scheduled task named 'OneDriveHealth', and leverages Filen cloud storage for C2; CERT-UA warns of rapid exploitation and provides mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.