logo

APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies

ID: 434e063b-ae9c-5fab-8f6f-7333d6e485e5

STIX ID: report--434e063b-ae9c-5fab-8f6f-7333d6e485e5

Feed Name: The Hacker News

Threat Score
92/100

Date Published: 2026-04-08

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

APT28 (aka Pawn Storm) has run a spear-phishing campaign since at least September 2025 to deliver a modular malware family dubbed PRISMEX against Ukrainian and allied targets; the campaign weaponizes zero-day vulnerabilities (CVE-2026-21509, CVE-2026-21513), leverages steganography, COM hijacking, and legitimate cloud services for C2, and deploys components (PrismexSheet, PrismexDrop, PrismexLoader, PrismexStager) that enable credential/exfiltration operations and, in some cases, destructive wiper actions—indicating a blend of espionage and sabotage objectives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.