APT28 Exploits Active Microsoft Office Zero-Day to Deliver Malware
ID: 3c347a26-ef9f-5915-95a6-a73edf4842fe
STIX ID: report--3c347a26-ef9f-5915-95a6-a73edf4842fe
Feed Name: GBHackers
**Operation Neusploit (APT28) exploits CVE-2026-21509 via weaponized RTFs to deliver two dropper variants—one deploying MiniDoor (an Outlook email stealer) and another using PixyNetLoader to load EhStoreShell.dll and a Covenant Grunt implant—targeting Ukraine, Slovakia, and Romania with geo-filtered delivery and persistence mechanisms; Microsoft released an emergency patch on 2026-01-26 but active exploitation continued afterward, and the report provides extensive IOCs and mitigation recommendations.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
