logo

Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days

ID: 766356ca-d37c-5745-ab97-0aedb1f6c4d3

STIX ID: report--766356ca-d37c-5745-ab97-0aedb1f6c4d3

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-02-03

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

APT28 (Fancy Bear) rapidly weaponized CVE-2026-21509 to run Operation Neusploit against organizations in Central and Eastern Europe using crafted RTFs that deploy dropper DLLs (MiniDoor for Outlook email theft and PixyNetLoader leading to a Covenant Grunt backdoor); attacks used localized phishing, server-side filtering, WebDAV/COM hijack techniques, and Filen.io for C2, and Microsoft issued an out-of-cycle patch which organizations are urged to apply immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.