logo

Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities

ID: 30e9c17f-14e0-50da-847c-49d31b7a5a92

STIX ID: report--30e9c17f-14e0-50da-847c-49d31b7a5a92

Feed Name: TrendAI Security Blog

Threat Score
92/100

Date Published: 2026-01-12

Date Updated: 2026-08-14

...
...

TrendAI Research attributes a high-confidence Pawn Storm (APT28) campaign — active since at least September 2025 and escalating in January 2026 — that deploys a modular malware suite named PRISMEX to target Ukrainian defense supply chains and NATO logistics. The campaign weaponizes two security feature bypass flaws (CVE-2026-21509 in Office OLE and CVE-2026-21513 in MSHTML), uses advanced steganography (a Bit Plane Round Robin algorithm) and fileless .NET execution via Covenant Grunt stagers, abuses legitimate cloud storage (Filen.io) for C2, and demonstrates capabilities for both espionage and destructive actions; the report includes IoC references, MITRE ATT&CK mappings, and immediate mitigations (patching, macro restrictions, registry audits, and network controls).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.