Operation MacroMaze: new APT28 campaign using basic tooling and legit infrastructure
ID: 4840c671-3da2-57a4-801a-c32e4f389c34
STIX ID: report--4840c671-3da2-57a4-801a-c32e4f389c34
Feed Name: Lab52 Blog
Threat Score
LAB52 describes "Operation MacroMaze," an APT28-attributed spear-phishing campaign (Sep 2025–Jan 2026) that uses malicious Word documents with INCLUDEPICTURE tracking and macro droppers to write VBS/BAT/CMD/HTM artifacts, create scheduled tasks for persistence, and exfiltrate collected system information via auto-submitting HTML to webhook.site endpoints; multiple macro and batch variants and associated IOCs (file hashes and webhook URLs) are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
