logo

APT28 Exploits Active Microsoft Office Zero-Day to Deliver Malware

ID: 3c347a26-ef9f-5915-95a6-a73edf4842fe

STIX ID: report--3c347a26-ef9f-5915-95a6-a73edf4842fe

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-02-03

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Operation Neusploit (APT28) exploits CVE-2026-21509 via weaponized RTFs to deliver two dropper variants—one deploying MiniDoor (an Outlook email stealer) and another using PixyNetLoader to load EhStoreShell.dll and a Covenant Grunt implant—targeting Ukraine, Slovakia, and Romania with geo-filtered delivery and persistence mechanisms; Microsoft released an emergency patch on 2026-01-26 but active exploitation continued afterward, and the report provides extensive IOCs and mitigation recommendations.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.