APT28 Hackers Exploiting Microsoft Office Vulnerability to Compromise Government Agencies
## APT28 Exploits Microsoft Office Vulnerability in Cyber Espionage Campaign
APT28 Exploits Microsoft Office Vulnerability in Cyber Espionage Campaign
Russian state-sponsored group APT28 has commenced a cyber espionage campaign targeting government and military entities in Europe. Primary targets include maritime and transport organizations in Poland, Ukraine, and Turkey. The group exploits a Microsoft Office vulnerability, CVE-2026-21509, allowing them to bypass protections and execute malicious code.
The attack begins with spear-phishing emails designed to resemble urgent official communications. These messages use geopolitical themes, such as weapons smuggling alerts or military training invitations, to deceive recipients. Upon opening the document, the exploit activates automatically, requiring no user interaction.
This "zero-click" capability makes the attack particularly potent against defense and diplomatic institutions. Trellix analysts identified the activity, noting the adversary's rapid weaponization of the flaw within a day of its disclosure.
The attack documents use embedded objects leveraging the WebDAV protocol, retrieving external payloads from attacker-controlled infrastructure. This approach disguises malicious traffic as legitimate, enabling intruders to establish undetected access.
Russian state-sponsored group APT28 has commenced a cyber espionage campaign targeting government and military entities in Europe.
Post-exploitation, hackers deploy custom malware, including the C++ implant "BeardShell" and the Outlook backdoor "NotDoor," to maintain access and exfiltrate intelligence.
The infection chain employs multiple obfuscation layers to bypass security controls. After the initial breach, a loader retrieves an encrypted image containing shellcode, executing the BeardShell backdoor in memory and avoiding disk-based detection.
Anti-analysis routines, such as timing checks, are used to detect security sandboxes. The attackers utilize the cloud storage service filen.io for command and control, blending malicious traffic with regular data. Organizations are advised to apply emergency Office patches and restrict the WebDAV protocol to mitigate these threats.
Based on reporting by Cyber Security News.




