logo

APT28 Uses Microsoft Office CVE-2026-21509 in Espionage-Focused Malware Attacks

ID: d7a082d2-3ea9-54dd-943d-4377487766cf

STIX ID: report--d7a082d2-3ea9-54dd-943d-4377487766cf

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-02-03

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

APT28 (UAC-0001) exploited Microsoft Office vulnerability CVE-2026-21509 in a multi-stage campaign delivering an Outlook email stealer (MiniDoor) and a loader (PixyNetLoader) that implants a COVENANT Grunt; the attacks targeted government, military and transport entities across multiple countries and employed COM object hijacking, steganographic shellcode in PNGs, DLL proxying, and cloud storage (filen.io) as C2, with active exploitation reported by Zscaler, CERT-UA and Trellix.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.