Op Neusploit: Russian APT28 Uses Microsoft Office Flaw in Malware Attacks
ID: 5ef17d8a-78b9-5658-9118-711eb0d5b790
STIX ID: report--5ef17d8a-78b9-5658-9118-711eb0d5b790
Feed Name: HackRead
Researchers uncovered Operation Neusploit, a targeted campaign attributed to APT28 that exploited CVE-2026-21509 in Microsoft Office OLE via malicious RTF documents to deploy droppers (MiniDoor and PixyNetLoader) and ultimately the Covenant Grunt implant; techniques include steganography, anti-analysis checks, Outlook-focused data theft and exfiltration via cloud services, with active exploitation observed even after an emergency Microsoft patch — organizations in Ukraine, Slovakia, and Romania are primary targets and should apply updates and avoid opening unexpected attachments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
