APT28 Hackers Exploiting Microsoft Office Vulnerability to Compromise Government Agencies
ID: a9ca103b-a3c3-532b-b0b5-6389ad62b7b8
STIX ID: report--a9ca103b-a3c3-532b-b0b5-6389ad62b7b8
Feed Name: cybersecurityNews.com
Russian state-sponsored actor APT28 is conducting a high-profile espionage campaign against government and military targets in Europe by exploiting Microsoft Office vulnerability CVE-2026-21509. Attackers use spear-phishing with weaponized documents that perform a zero-click exploit, retrieve payloads via WebDAV from attacker-controlled infrastructure and cloud storage (filen.io), and deploy in-memory backdoors (BeardShell) and an Outlook backdoor (NotDoor) with anti-analysis and persistent C2 mechanisms; Trellix observed the flaw weaponized within 24 hours of disclosure. Recommended mitigations include applying emergency Office patches, restricting WebDAV, and enforcing strict email filtering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
