Russian APT28 Exploit Zero-Day Hours After Microsoft Discloses Office Vulnerability
ID: ceb6a8b1-e5ce-5f18-a1eb-a907a2661798
STIX ID: report--ceb6a8b1-e5ce-5f18-a1eb-a907a2661798
Feed Name: The Cyber Express
CERT‑UA reports that APT28 rapidly weaponized a Microsoft Office zero‑day (CVE‑2026‑21509) within 24 hours of public disclosure to target Ukrainian government bodies and EU organizations with malicious DOC files that deploy the Covenant post‑exploitation framework via a WebDAV download, COM hijacking (EhStoreShell.dll), and a scheduled task named OneDriveHealth; the advisory includes IoCs, targeted email lures, and mitigation guidance (patching, registry protections, and blocking Filen.io C2 infrastructure).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
