Steganography & Sabotage: Inside Pawn Storm’s PRISMEX Offensive Against NATO Logistics
ID: a4048229-6952-5483-aa08-84890a6d5ed5
STIX ID: report--a4048229-6952-5483-aa08-84890a6d5ed5
Feed Name: securityonline.info
Trend Micro reports that Pawn Storm (APT28) has escalated operations in early 2026 with a coordinated campaign using a modular malware suite named PRISMEX — comprised of PrismexSheet, PrismexDrop, PrismexLoader, and PrismexStager — which employs advanced steganography, fileless execution, COM hijacking persistence, and abuse of the Filen.io cloud service for C2; the group was observed exploiting two zero-day vulnerabilities in MSHTML and Microsoft Office (CVE-2026-21513 and CVE-2026-21509), conducting targeted intrusions against Ukrainian defense entities and NATO logistics hubs across multiple European countries with potential espionage and sabotage (including wiper functionality).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
