APT28 Uses Microsoft Office CVE-2026-21509 in Espionage-Focused Malware Attacks
ID: d7a082d2-3ea9-54dd-943d-4377487766cf
STIX ID: report--d7a082d2-3ea9-54dd-943d-4377487766cf
Feed Name: The Hacker News
Threat Score
APT28 (UAC-0001) exploited Microsoft Office vulnerability CVE-2026-21509 in a multi-stage campaign delivering an Outlook email stealer (MiniDoor) and a loader (PixyNetLoader) that implants a COVENANT Grunt; the attacks targeted government, military and transport entities across multiple countries and employed COM object hijacking, steganographic shellcode in PNGs, DLL proxying, and cloud storage (filen.io) as C2, with active exploitation reported by Zscaler, CERT-UA and Trellix.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
