logo

Russia-linked APT28 uses PRISMEX to infiltrate Ukraine and allied infrastructure with advanced tactics

ID: f6cd0e68-404f-548e-8982-3f7f7eeaf737

STIX ID: report--f6cd0e68-404f-548e-8982-3f7f7eeaf737

Feed Name: Security Affairs

Threat Score
92/100

Date Published: 2026-04-08

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

APT28 (aka Pawn Storm/Fancy Bear) is conducting a spear-phishing campaign active since September 2025 that deploys the PRISMEX malware suite against Ukrainian and allied government, military, and logistics targets; the campaign exploits CVE-2026-21509 and CVE-2026-21513, uses steganography, COM hijacking, and fileless Covenant-based payloads, and blends C2 traffic through Filen.io to support long-term espionage and potential disruptive operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.