logo

Steganography & Sabotage: Inside Pawn Storm’s PRISMEX Offensive Against NATO Logistics

ID: a4048229-6952-5483-aa08-84890a6d5ed5

STIX ID: report--a4048229-6952-5483-aa08-84890a6d5ed5

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-01

Date Updated: 2026-04-23

Author: Ddos

...
...

Trend Micro reports that Pawn Storm (APT28) has escalated operations in early 2026 with a coordinated campaign using a modular malware suite named PRISMEX — comprised of PrismexSheet, PrismexDrop, PrismexLoader, and PrismexStager — which employs advanced steganography, fileless execution, COM hijacking persistence, and abuse of the Filen.io cloud service for C2; the group was observed exploiting two zero-day vulnerabilities in MSHTML and Microsoft Office (CVE-2026-21513 and CVE-2026-21509), conducting targeted intrusions against Ukrainian defense entities and NATO logistics hubs across multiple European countries with potential espionage and sabotage (including wiper functionality).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.