logo

When Documents Become the Attack Vector: Inside APT28’s Latest Microsoft Office Exploit

ID: 233163f8-34b3-5e21-b70c-2166e84fb24d

STIX ID: report--233163f8-34b3-5e21-b70c-2166e84fb24d

Feed Name: Security Boulevard

Threat Score
88/100

Date Published: 2026-02-04

Date Updated: 2026-04-22

Author: Aditya Kumar

...
...

APT28 is actively exploiting a Microsoft Office zero-day delivered via specially crafted Office and RTF documents in targeted phishing emails; the exploit achieves unauthorized code execution without macros, allowing lightweight loaders to establish C2 while blending into normal Office activity. The report emphasizes detection blind spots when attackers abuse trusted processes and recommends behavior-focused detection and continuous breach validation (Seceon’s aiSIEM/aiXDR/aiBAS360) to correlate user, endpoint, and network signals and detect post-exploitation behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.