logo

UAC-0001 (APT28) Attack Detection: russia-Backed Actor Actively Exploits CVE-2026-21509 Targeting Ukraine and the EU

ID: 2fbedfe2-f3ff-5013-98a5-b6c01fee763c

STIX ID: report--2fbedfe2-f3ff-5013-98a5-b6c01fee763c

Feed Name: SOC Prime Blog

Threat Score
90/100

Date Published: 2026-02-02

Date Updated: 2026-04-30

Author: Daryna Olyniychuk

...
...

CERT‑UA reported that UAC-0001 (APT28) rapidly weaponized Microsoft Office zero-day CVE-2026-21509 in late January 2026 to deliver the COVENANT framework to Ukrainian state bodies and later EU organizations via malicious Word documents that fetch a shortcut and launch a DLL (EhStoreShell.dll) using COM hijacking and a scheduled task (OneDriveHealth); C2 used Filen cloud storage and metadata shows one sample was created within 24 hours of public disclosure, indicating active exploitation and rapid campaign expansion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.