CVE-2026-21509: APT28 Actively Exploits Microsoft Office Vulnerability in Ukraine
ID: 057604e6-f8cb-560d-baa3-ccff568c534d
STIX ID: report--057604e6-f8cb-560d-baa3-ccff568c534d
Feed Name: SOCRadar Blog
This bulletin details active exploitation of CVE-2026-21509 by UAC-0001 (APT28) targeting Ukrainian government and diplomatic organizations: attackers deliver malicious Microsoft Word documents via phishing, use WebDAV to fetch payloads, drop a malicious EhStoreShell.dll and PNG-contained shellcode, perform COM hijacking and create a OneDriveHealth scheduled task to load the DLL and deploy the COVENANT framework (using Filen cloud infrastructure); the report lists affected Office versions, multiple file and network IoCs, and recommends applying Microsoft's out-of-band patches, registry hardening, and user training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
