Russian hackers exploit recently patched Microsoft Office bug in attacks
ID: fd5f1130-9ff2-5a9b-aee5-e7169c35c3ff
STIX ID: report--fd5f1130-9ff2-5a9b-aee5-e7169c35c3ff
Feed Name: Bleeping Computer
CERT-UA reports that Russian-linked APT28 (Fancy Bear) has been actively exploiting a recently patched Microsoft Office zero-day (CVE-2026-21509) to deliver a loader and the COVENANT framework via malicious DOC files; the multi-stage chain uses WebDAV downloads, COM hijacking to load EhStoreShell.dll, shellcode hidden in an image, and a scheduled task (OneDriveHealth), with Filen used for command-and-control. Attacks targeted Ukrainian and EU government-related recipients; Microsoft issued an emergency patch and defenders are advised to apply updates, restart affected Office apps, follow registry mitigations if patching is delayed, and monitor or block Filen-related connections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
