logo

Op Neusploit: Russian APT28 Uses Microsoft Office Flaw in Malware Attacks

ID: 5ef17d8a-78b9-5658-9118-711eb0d5b790

STIX ID: report--5ef17d8a-78b9-5658-9118-711eb0d5b790

Feed Name: HackRead

Threat Score
88/100

Date Published: 2026-02-03

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Researchers uncovered Operation Neusploit, a targeted campaign attributed to APT28 that exploited CVE-2026-21509 in Microsoft Office OLE via malicious RTF documents to deploy droppers (MiniDoor and PixyNetLoader) and ultimately the Covenant Grunt implant; techniques include steganography, anti-analysis checks, Outlook-focused data theft and exfiltration via cloud services, with active exploitation observed even after an emergency Microsoft patch — organizations in Ukraine, Slovakia, and Romania are primary targets and should apply updates and avoid opening unexpected attachments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.