Russia-linked APT28 uses PRISMEX to infiltrate Ukraine and allied infrastructure with advanced tactics
ID: f6cd0e68-404f-548e-8982-3f7f7eeaf737
STIX ID: report--f6cd0e68-404f-548e-8982-3f7f7eeaf737
Feed Name: Security Affairs
Threat Score
APT28 (aka Pawn Storm/Fancy Bear) is conducting a spear-phishing campaign active since September 2025 that deploys the PRISMEX malware suite against Ukrainian and allied government, military, and logistics targets; the campaign exploits CVE-2026-21509 and CVE-2026-21513, uses steganography, COM hijacking, and fileless Covenant-based payloads, and blends C2 traffic through Filen.io to support long-term espionage and potential disruptive operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
