logo

APT28 exploits Microsoft Office flaw in Operation Neusploit

ID: f15257b6-4f29-50b0-b794-a351dbe22982

STIX ID: report--f15257b6-4f29-50b0-b794-a351dbe22982

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-02-03

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

**Operation Neusploit:** Russia-linked APT28 weaponized a newly disclosed Microsoft Office zero‑day (CVE-2026-21509) to deliver weaponized RTFs that drop MiniDoor (an email‑stealing Outlook VBA implant) and a PixyNetLoader chain that uses COM hijacking, steganography, and DLL proxying to load a Covenant Grunt in memory; the campaign targeted users in Central and Eastern Europe with localized lures and was observed actively exploiting the vulnerability in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.