Pawn Storm Campaign Utilizes PRISMEX to Target Ukrainian Defense Infrastructure
ID: 56035a73-d547-5d91-9d6a-d8142af7aa2c
STIX ID: report--56035a73-d547-5d91-9d6a-d8142af7aa2c
Feed Name: ThreatCluster
Threat Score
Pawn Storm has launched a high-severity campaign (PRISMEX) targeting Ukrainian defense supply chains and Western humanitarian/military aid, exploiting CVE-2026-21509. The PRISMEX suite includes a dropper, steganography loader, and a Covenant Grunt implant enabling fileless execution and EDR evasion; the campaign leverages steganography, cloud abuse, and email-based backdoors and is linked to the NotDoor ecosystem.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
