logo

CVE-2026-21509: APT28 Actively Exploits Microsoft Office Vulnerability in Ukraine

ID: 057604e6-f8cb-560d-baa3-ccff568c534d

STIX ID: report--057604e6-f8cb-560d-baa3-ccff568c534d

Feed Name: SOCRadar Blog

Threat Score
90/100

Date Published: 2026-02-03

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

This bulletin details active exploitation of CVE-2026-21509 by UAC-0001 (APT28) targeting Ukrainian government and diplomatic organizations: attackers deliver malicious Microsoft Word documents via phishing, use WebDAV to fetch payloads, drop a malicious EhStoreShell.dll and PNG-contained shellcode, perform COM hijacking and create a OneDriveHealth scheduled task to load the DLL and deploy the COVENANT framework (using Filen cloud infrastructure); the report lists affected Office versions, multiple file and network IoCs, and recommends applying Microsoft's out-of-band patches, registry hardening, and user training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.