Fancy Bear Exploits Microsoft Office Flaw in Ukraine, EU Cyber-Attacks
ID: 53a30349-b2a5-5911-a011-a7faf0556a17
STIX ID: report--53a30349-b2a5-5911-a011-a7faf0556a17
Feed Name: Infosecurity Magazine (News)
CERT-UA reported that Russian-linked APT Fancy Bear (APT28) exploited Microsoft Office vulnerability CVE-2026-21509 via malicious Word documents (e.g., ‘Consultation_Topics_Ukraine(Final).doc’ and ‘BULLETEN_H.doc’) to download an LNK payload that created EhStoreShell.dll and SplashScreen.png, modified a COM CLSID for hijacking, and scheduled a OneDriveHealth task to restart explorer.exe and load the DLL, ultimately launching the Covenant .NET C2 using Filen cloud storage; Microsoft confirmed in-the-wild exploitation and urged applying updates and registry mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
