logo

Operation Neusploit: APT28 Uses CVE-2026-21509

ID: 0ef85df5-0c7b-5165-9e95-194037dd3f29

STIX ID: report--0ef85df5-0c7b-5165-9e95-194037dd3f29

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2026-02-03

Date Updated: 2026-05-01

...
...

**Operation Neusploit** is a multi-stage APT campaign (linked to APT28) that leverages CVE-2026-21509 to deliver two DLL dropper variants: one installs an Outlook VBA stealer named MiniDoor to exfiltrate email, and the other (PixyNetLoader) deploys a COM-hijacking DLL (EhStoreShell.dll) that extracts steganographic shellcode from a PNG and hosts a .NET Covenant Grunt implant via CLR hosting; the report details technical TTPs, persistence (registry COM entries, scheduled task, macro downgrading), IOCs (mutex names, file paths, registry keys, scheduled task XML), and includes links to extracted artifacts and analysis code.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.