Friday, August 14, 2026
LIVE
Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///
Subscribe
The Levant
Independent · Digital
The Levant Herald
PoliticsAI-assisted

APT28 Hackers Exploiting Microsoft Office Vulnerability to Compromise Government Agencies

## APT28 Exploits Microsoft Office Vulnerability in Cyber Espionage Campaign

APT28 Exploits Microsoft Office Vulnerability in Cyber Espionage Campaign

Russian state-sponsored group APT28 has commenced a cyber espionage campaign targeting government and military entities in Europe. Primary targets include maritime and transport organizations in Poland, Ukraine, and Turkey. The group exploits a Microsoft Office vulnerability, CVE-2026-21509, allowing them to bypass protections and execute malicious code.

The attack begins with spear-phishing emails designed to resemble urgent official communications. These messages use geopolitical themes, such as weapons smuggling alerts or military training invitations, to deceive recipients. Upon opening the document, the exploit activates automatically, requiring no user interaction.

This "zero-click" capability makes the attack particularly potent against defense and diplomatic institutions. Trellix analysts identified the activity, noting the adversary's rapid weaponization of the flaw within a day of its disclosure.

The attack documents use embedded objects leveraging the WebDAV protocol, retrieving external payloads from attacker-controlled infrastructure. This approach disguises malicious traffic as legitimate, enabling intruders to establish undetected access.

Russian state-sponsored group APT28 has commenced a cyber espionage campaign targeting government and military entities in Europe.
Omar Sabbagh · The Levant Herald

Post-exploitation, hackers deploy custom malware, including the C++ implant "BeardShell" and the Outlook backdoor "NotDoor," to maintain access and exfiltrate intelligence.

The infection chain employs multiple obfuscation layers to bypass security controls. After the initial breach, a loader retrieves an encrypted image containing shellcode, executing the BeardShell backdoor in memory and avoiding disk-based detection.

Advertisement

Anti-analysis routines, such as timing checks, are used to detect security sandboxes. The attackers utilize the cloud storage service filen.io for command and control, blending malicious traffic with regular data. Organizations are advised to apply emergency Office patches and restrict the WebDAV protocol to mitigate these threats.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories