logo

Russia-linked APT28 attackers already abusing new Microsoft Office zero-day

ID: 8b0471cc-f82a-57bd-8d0d-5751c5f3b5b0

STIX ID: report--8b0471cc-f82a-57bd-8d0d-5751c5f3b5b0

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2026-02-02

Date Updated: 2026-04-26

Author: Carly Page

...
...

CERT-UA reports that Russia-linked APT28 is actively exploiting a Microsoft Office zero-day (CVE-2026-21509) via malicious Word documents (e.g., "Consultation_Topics_Ukraine(Final).doc") to fetch payloads over WebDAV, drop a disguised DLL and image-embedded shellcode, achieve persistence through COM hijacking and a scheduled task, and deploy the COVENANT post-exploitation framework while routing traffic through cloud storage; multiple EU-targeted documents and rapidly registered infrastructure were observed and Microsoft has released patches though uptake may lag.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.