APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies
ID: 434e063b-ae9c-5fab-8f6f-7333d6e485e5
STIX ID: report--434e063b-ae9c-5fab-8f6f-7333d6e485e5
Feed Name: The Hacker News
APT28 (aka Pawn Storm) has run a spear-phishing campaign since at least September 2025 to deliver a modular malware family dubbed PRISMEX against Ukrainian and allied targets; the campaign weaponizes zero-day vulnerabilities (CVE-2026-21509, CVE-2026-21513), leverages steganography, COM hijacking, and legitimate cloud services for C2, and deploys components (PrismexSheet, PrismexDrop, PrismexLoader, PrismexStager) that enable credential/exfiltration operations and, in some cases, destructive wiper actions—indicating a blend of espionage and sabotage objectives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
