Operation Neusploit: APT28 Uses CVE-2026-21509
ID: 0ef85df5-0c7b-5165-9e95-194037dd3f29
STIX ID: report--0ef85df5-0c7b-5165-9e95-194037dd3f29
Feed Name: Zscaler Security Research Blog
**Operation Neusploit** is a multi-stage APT campaign (linked to APT28) that leverages CVE-2026-21509 to deliver two DLL dropper variants: one installs an Outlook VBA stealer named MiniDoor to exfiltrate email, and the other (PixyNetLoader) deploys a COM-hijacking DLL (EhStoreShell.dll) that extracts steganographic shellcode from a PNG and hosts a .NET Covenant Grunt implant via CLR hosting; the report details technical TTPs, persistence (registry COM entries, scheduled task, macro downgrading), IOCs (mutex names, file paths, registry keys, scheduled task XML), and includes links to extracted artifacts and analysis code.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
