Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitystate-sponsored-espionagegovernment-diplomatic-threatrapid-weaponization

APT28 Exploitation of Microsoft Office Zero-Day CVE-2026-21509 Against Ukraine and EU Targets

Updated 2mo agoFirst seen Feb 2, 202619 sources

Ukraine’s CERT-UA reported active exploitation of a Microsoft Office zero-day, CVE-2026-21509 (a security feature bypass), attributed to Russia-linked UAC-0001 / APT28 (Fancy Bear) and used to target Ukrainian government bodies and organizations across the EU. Microsoft disclosed the flaw with a warning that it was already being exploited in the wild, and CERT-UA observed rapid weaponization: a lure document titled Consultation_Topics_Ukraine(Final).doc appeared shortly after disclosure and was themed around EU discussions on Ukraine, suggesting the exploit chain was prepared in advance.

CERT-UA also described a parallel phishing campaign impersonating the Ukrhydrometeorological Center, sent to 60+ recipients largely in Ukrainian central executive bodies. The attack chain described includes opening a malicious DOC that triggers a WebDAV connection to attacker infrastructure, downloads a shortcut (.lnk) used to stage additional payloads, and deploys components including a DLL masquerading as a legitimate Windows component (e.g., EhStoreShell.dll) with shellcode hidden in a decoy file (e.g., SplashScreen.png), alongside persistence techniques such as COM hijacking (registry modification) and scheduled task creation.

Share:
APT28 Exploitation of Microsoft Office Zero-Day CVE-2026-21509 Against Ukraine and EU Targets
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

12 events from the most recent confirmed update back to the earliest known activity.

12 EVENTS
Feb 9, 20264mo ago

SANS analysis extracts additional IOCs from disguised RTF lure documents

A SANS ISC diary showed that reported .doc lure files were actually RTF documents and demonstrated how to extract embedded URLs and other indicators from them. The analysis surfaced domains, UNC paths, and malformed WebDAV-style references that could aid defenders investigating the campaign.

Feb 4, 20265mo ago

Trellix identifies broader sector targeting and additional implants

Subsequent reporting expanded the victimology beyond government agencies to maritime, transport, military, and NATO-aligned organizations in countries including Poland, Ukraine, and Turkey. Trellix said the campaign used additional implants such as BEARDSHELL and NotDoor, with command-and-control traffic routed through Filen cloud storage.

Feb 3, 20265mo ago

CISA adds CVE-2026-21509 to the Known Exploited Vulnerabilities catalog

Following confirmation of in-the-wild exploitation, CISA added CVE-2026-21509 to its Known Exploited Vulnerabilities list. The move underscored the urgency for organizations to patch affected Microsoft Office installations.

Feb 2, 20265mo ago

CERT-UA publishes exploit-chain details and defensive guidance

On 2026-02-02, CERT-UA described the attack chain using WebDAV retrieval, a malicious shortcut, EhStoreShell.dll, shellcode hidden in SplashScreen.png, COM hijacking, and a scheduled task named OneDriveHealth. It warned attacks were likely to increase due to slow patching and advised blocking indicators and Filen-related traffic where appropriate.

CERT-UA attributes Ukrainian and EU targeting to UAC-0001/APT28

CERT-UA publicly linked the exploitation of CVE-2026-21509 against Ukrainian government agencies and EU organizations to UAC-0001, also known as APT28 or Fancy Bear. The attribution connected the activity to Russia's GRU-linked espionage operations.

Jan 29, 20265mo ago

Researchers document dual malware chains: MiniDoor and PixyNetLoader

Technical analysis revealed two main post-exploitation paths in the campaign: one deploying the Outlook-focused MiniDoor implant for email theft and forwarding, and another using PixyNetLoader to stage follow-on payloads. Reports also linked related tooling including NotDoor, BEARDSHELL, and Covenant Grunt to the activity.

Operation Neusploit targets Central and Eastern Europe

Zscaler ThreatLabz reported a broader APT28 espionage campaign, dubbed Operation Neusploit, targeting organizations in Ukraine, Slovakia, Romania, and other Central and Eastern European countries. The campaign used localized RTF or Word phishing lures to exploit CVE-2026-21509.

CERT-UA observes phishing campaign targeting Ukrainian government entities

CERT-UA identified malicious Office lures themed around EU COREPER consultations on Ukraine and fake bulletins from the Ukrainian hydrometeorological center. The emails were sent to more than 60 addresses, mostly tied to Ukrainian state authorities and government-related organizations.

APT28 begins exploiting CVE-2026-21509 within days of disclosure

Researchers reported that Russia-linked APT28 rapidly weaponized CVE-2026-21509 within 24 to 72 hours of Microsoft's patch and disclosure. Early exploitation was observed around 2026-01-28 to 2026-01-29, showing the group quickly adapted the flaw for phishing-based intrusion campaigns.

Jan 28, 20265mo ago

Trellix reports a 72-hour spearphishing wave across nine countries

Trellix disclosed a concentrated 72-hour APT28 spearphishing operation beginning on 2026-01-28 that used at least 29 lures sent from compromised government email accounts. The campaign targeted diplomatic, defense, maritime, transport, and logistics organizations in nine countries, primarily in Eastern Europe.

Jan 26, 20265mo ago

Microsoft discloses and patches CVE-2026-21509 as an exploited Office zero-day

On 2026-01-26, Microsoft released an out-of-band security update for CVE-2026-21509, a Microsoft Office security feature bypass affecting multiple Office versions. Microsoft warned that the flaw was already being actively exploited in the wild.

Sep 1, 202510mo ago

Trend Micro links APT28 PRISMEX campaign to Ukraine and allied targets

Trend Micro uncovered an APT28 spear-phishing campaign active since September 2025 targeting Ukraine’s defense supply chain, aid infrastructure, and government entities in Central and Eastern Europe. The operation used military- and aid-themed RTF lures exploiting CVE-2026-21509 and CVE-2026-21513 and deployed the PRISMEX toolkit, including a dropper, loader, and Covenant-based implant using cloud services such as Filen.io for encrypted command-and-control.

APT28 deploys PRISMEX malware in espionage campaign against Ukraine and allies | brief | SC Media
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

35 LINKEDOpen in app
Threat actors
3 linked
Affected products
4 linked
Microsoft OfficeWindows ExplorerWinrarWinrar
Organizations
16 linked
Microsoft CorporationFilen.ioSecurity AffairsTrend MicroFilenTrellixZscalerPolySwarmBlackpoint CyberSOCRadarThreatrayBugcrowdTinesDeutsche FlugsicherungUkrhydrometeorological CenterUkrainian Hydrometeorological Center
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

APT28 Exploitation of Microsoft Office Zero-Day CVE-2026-21509 Against Ukraine and EU Targets | Mallory