Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareUsed by 2 actorsExploits 2 CVEs

PRISMEX

PRISMEX is a malware suite attributed with high confidence by Trend Micro to the Russia-linked APT28 threat group, also known as Fancy Bear and Pawn Storm. The campaign using PRISMEX has been active since at least September 2025 and intensified in January 2026. It targets Ukraine’s defense supply chain and allied organizations, including government, military, defense, aid, logistics, and other critical support entities in Central and Eastern Europe, with reported targeting including Ukraine, the Czech Republic, Poland, Romania, Slovakia, Slovenia, and Turkey.

The malware is used in spear-phishing operations themed around military training, aid, weather alerts, weapon smuggling, and related logistics. Reported lures include malicious RTF attachments and decoy documents resembling Ukrainian drone inventories, supplier price lists, and military logistics forms. The infection chain reportedly exploited CVE-2026-21509 and CVE-2026-21513 for initial access and silent payload execution.

PRISMEX is described as a multi-component toolkit including a dropper, loader, and implant/stager, with component names reported as PrismexDrop, PrismexLoader, PrismexStager, and PrismexSheet. Its capabilities include stealthy, fileless execution, persistence, encrypted command-and-control, espionage, and sabotage. Trend Micro reported that PRISMEX combines advanced steganography, COM hijacking, and abuse of legitimate cloud services for command and control. PrismexDrop reportedly decrypts payloads, drops files, and establishes persistence via COM hijacking and a scheduled task that restarts explorer.exe. PrismexLoader reportedly acts as a proxy DLL, mimics legitimate system behavior, and uses a custom steganography method called Bit Plane Round Robin to extract hidden payloads from images, then executes them in memory via .NET runtime loading. PrismexStager is described as a heavily obfuscated Covenant-based .NET Grunt stager used for command-and-control and task execution.

For command-and-control, PRISMEX reportedly abuses legitimate cloud services, specifically Filen.io, to blend encrypted traffic with normal activity. The malware suite is explicitly described as supporting both espionage and sabotage, including wiper commands. Reporting also states that researchers believe PRISMEX represents an evolution of the NotDoor ecosystem. High-confidence indicators and artifacts mentioned in the reporting include use of Filen.io for C2, WebDAV infrastructure in the exploit chain, COM hijacking for persistence, scheduled-task-based explorer.exe restart behavior, malicious LNK execution, and image-based steganographic payload concealment.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

2 CVES
CVE-2026-21509Microsoft Office Shell.Explorer.1 OLE Security Feature BypassExploited in the wild

Prismex leverages multiple Windows vulnerabilities, Trend Micro said in its late March blog post, including "a confirmed Windows zero-day" in CVE-2026-21513 as well as Microsoft Office bug CVE-2026-21509. | Trend Micro said the actor ... has been using a collection of malware components known as "Prismex" to target the defense supply-chain of Ukraine and its allies ... "Prismex combines advanced steganography, component object model (COM) hijacking, and legitimate cloud service abuse for command and control," ... The special malware includes both espionage and sabotage capabilities, with the latter including wiper commands.

via dark readingdarkreading.com
CVE-2026-21513Microsoft MSHTML Framework Security Feature BypassExploited in the wild

Trend Micro said the actor ... has been using a collection of malware components known as "Prismex" to target the defense supply-chain of Ukraine and its allies ... "Prismex combines advanced steganography, component object model (COM) hijacking, and legitimate cloud service abuse for command and control," ... The special malware includes both espionage and sabotage capabilities, with the latter including wiper commands. | Prismex leverages multiple Windows vulnerabilities, Trend Micro said in its late March blog post, including "a confirmed Windows zero-day" in CVE-2026-21513 as well as Microsoft Office bug CVE-2026-21509.

via dark readingdarkreading.com
THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
APT28

Trend Micro said the actor ... has been using a collection of malware components known as "Prismex" to target the defense supply-chain of Ukraine and its allies ... "Prismex combines advanced steganography, component object model (COM) hijacking, and legitimate cloud service abuse for command and control," ... The special malware includes both espionage and sabotage capabilities, with the latter including wiper commands.

via dark readingdarkreading.com
APT29

Trend Micro said the actor ... has been using a collection of malware components known as "Prismex" to target the defense supply-chain of Ukraine and its allies ... "Prismex combines advanced steganography, component object model (COM) hijacking, and legitimate cloud service abuse for command and control," ... The special malware includes both espionage and sabotage capabilities, with the latter including wiper commands.

via dark readingdarkreading.com
MITRE ATT&CK

Techniques & procedures

10 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566.001Spearphishing AttachmentEvidence2

Spear-phishing emails, themed around military training or aid, deliver malicious RTF files that trigger the exploitation.

Execution

2 techniques
T1059.005Visual BasicEvidence1

The researchers detailed decoy documents and targeting, such as a malicious Excel files showing realistic decoy content once macros are enabled, including Ukrainian drone inventories, supplier price lists, and military logistics forms.

T1203Exploitation for Client ExecutionEvidence3

The campaign... exploits newly disclosed vulnerabilities, including CVE-2026-21509 and CVE-2026-21513, to bypass security measures and gain initial access.

Persistence

1 technique
T1546.015Component Object Model HijackingEvidence1

"Prismex combines advanced steganography, component object model (COM) hijacking, and legitimate cloud service abuse for command and control," the blog read.

Privilege Escalation

2 techniques
T1068Exploitation for Privilege EscalationEvidence1

Prismex leverages multiple Windows vulnerabilities, Trend Micro said in its late March blog post, including "a confirmed Windows zero-day" in CVE-2026-21513 as well as Microsoft Office bug CVE-2026-21509.

T1546.015Component Object Model HijackingEvidence1

"Prismex combines advanced steganography, component object model (COM) hijacking, and legitimate cloud service abuse for command and control," the blog read.

Stealth

1 technique
T1027.003SteganographyEvidence4

"Prismex combines advanced steganography, component object model (COM) hijacking, and legitimate cloud service abuse for command and control," the blog read.

Command and Control

2 techniques
T1071Application Layer ProtocolEvidence1

The final component, PrismexStager, connects to command-and-control servers via Filen.io cloud services. This helps attackers blend malicious traffic with normal encrypted communications, making detection harder while enabling data exfiltration and remote control.

T1102Web ServiceEvidence3

"Prismex combines advanced steganography, component object model (COM) hijacking, and legitimate cloud service abuse for command and control," the blog read.

Exfiltration

1 technique
T1048Exfiltration Over Alternative ProtocolEvidence1

Victims who open the attached RTF file trigger exploitation of CVE-2026-21509, which bypasses security controls and forces the system to connect to an attacker-controlled WebDAV server. This automatically retrieves and executes a malicious LNK file without further user interaction.

Impact

1 technique
T1485Data DestructionEvidence1

The special malware includes both espionage and sabotage capabilities, with the latter including wiper commands.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities2

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping10

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.