Fancy Bear Returns: APT28 Exploits Office Flaw in “Operation Neusploit”
ID: 6cf4aaae-e755-5a29-b1a5-a45b06be91e9
STIX ID: report--6cf4aaae-e755-5a29-b1a5-a45b06be91e9
Feed Name: securityonline.info
Zscaler ThreatLabz reports that Russia-linked APT28 (Fancy Bear) launched "Operation Neusploit" targeting Ukraine, Slovakia, and Romania by weaponizing CVE-2026-21509 in Microsoft RTF files to deploy a multi-stage loader (PixyNetLoader) and a streamlined implant (MiniDoor) that steals email data; the campaign uses COM hijacking, DLL proxying, steganography (PNG-embedded shellcode), and Filen API-based C2, with exploitation observed days after Microsoft issued an out-of-band patch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
