logo

APT28 Hackers Exploiting Microsoft Office Vulnerability to Compromise Government Agencies

ID: a9ca103b-a3c3-532b-b0b5-6389ad62b7b8

STIX ID: report--a9ca103b-a3c3-532b-b0b5-6389ad62b7b8

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-02-05

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Russian state-sponsored actor APT28 is conducting a high-profile espionage campaign against government and military targets in Europe by exploiting Microsoft Office vulnerability CVE-2026-21509. Attackers use spear-phishing with weaponized documents that perform a zero-click exploit, retrieve payloads via WebDAV from attacker-controlled infrastructure and cloud storage (filen.io), and deploy in-memory backdoors (BeardShell) and an Outlook backdoor (NotDoor) with anti-analysis and persistent C2 mechanisms; Trellix observed the flaw weaponized within 24 hours of disclosure. Recommended mitigations include applying emergency Office patches, restricting WebDAV, and enforcing strict email filtering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.