logo

APT28 Leverages CVE-2026-21509 in Operation Neusploit

ID: dc146d14-7c49-5dc9-b9cb-3698597b991a

STIX ID: report--dc146d14-7c49-5dc9-b9cb-3698597b991a

Feed Name: Security Boulevard

Threat Score
90/100

Date Published: 2026-02-02

Date Updated: 2026-04-22

Author: Sudeep Singh (Sr. Manager, APT Research)

...
...

Zscaler ThreatLabz documents "Operation Neusploit," an active APT28 campaign exploiting CVE-2026-21509 in specially crafted RTF email attachments to deploy two dropper variants that install an Outlook VBA email stealer (MiniDoor) and a multi-stage loader (PixyNetLoader) which ultimately executes a Covenant Grunt implant via steganography, COM hijacking, and scheduled tasks; the report includes technical analysis, MITRE ATT&CK mappings, and extensive IOCs for remediation and detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.