APT28 exploits Microsoft Office flaw in Operation Neusploit
ID: f15257b6-4f29-50b0-b794-a351dbe22982
STIX ID: report--f15257b6-4f29-50b0-b794-a351dbe22982
Feed Name: Security Affairs
Threat Score
**Operation Neusploit:** Russia-linked APT28 weaponized a newly disclosed Microsoft Office zero‑day (CVE-2026-21509) to deliver weaponized RTFs that drop MiniDoor (an email‑stealing Outlook VBA implant) and a PixyNetLoader chain that uses COM hijacking, steganography, and DLL proxying to load a Covenant Grunt in memory; the campaign targeted users in Central and Eastern Europe with localized lures and was observed actively exploiting the vulnerability in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
