Russia-linked APT28 attackers already abusing new Microsoft Office zero-day
ID: 8b0471cc-f82a-57bd-8d0d-5751c5f3b5b0
STIX ID: report--8b0471cc-f82a-57bd-8d0d-5751c5f3b5b0
Feed Name: The Register (Security)
CERT-UA reports that Russia-linked APT28 is actively exploiting a Microsoft Office zero-day (CVE-2026-21509) via malicious Word documents (e.g., "Consultation_Topics_Ukraine(Final).doc") to fetch payloads over WebDAV, drop a disguised DLL and image-embedded shellcode, achieve persistence through COM hijacking and a scheduled task, and deploy the COVENANT post-exploitation framework while routing traffic through cloud storage; multiple EU-targeted documents and rapidly registered infrastructure were observed and Microsoft has released patches though uptake may lag.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
