logo

Russian APT28 Exploit Zero-Day Hours After Microsoft Discloses Office Vulnerability

ID: ceb6a8b1-e5ce-5f18-a1eb-a907a2661798

STIX ID: report--ceb6a8b1-e5ce-5f18-a1eb-a907a2661798

Feed Name: The Cyber Express

Threat Score
90/100

Date Published: 2026-02-02

Date Updated: 2026-04-23

Author: Mihir Bagwe

...
...

CERT‑UA reports that APT28 rapidly weaponized a Microsoft Office zero‑day (CVE‑2026‑21509) within 24 hours of public disclosure to target Ukrainian government bodies and EU organizations with malicious DOC files that deploy the Covenant post‑exploitation framework via a WebDAV download, COM hijacking (EhStoreShell.dll), and a scheduled task named OneDriveHealth; the advisory includes IoCs, targeted email lures, and mitigation guidance (patching, registry protections, and blocking Filen.io C2 infrastructure).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.