{"id":209490,"date":"2026-02-03T04:12:00","date_gmt":"2026-02-03T09:12:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/02\/03\/apt28-uses-microsoft-office-cve-2026-21509-in-espionage-focused-malware-attacks\/"},"modified":"2026-02-03T08:10:08","modified_gmt":"2026-02-03T13:10:08","slug":"apt28-uses-microsoft-office-cve-2026-21509-in-espionage-focused-malware-attacks","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/02\/03\/apt28-uses-microsoft-office-cve-2026-21509-in-espionage-focused-malware-attacks\/","title":{"rendered":"APT28 Uses Microsoft Office CVE-2026-21509 in Espionage-Focused Malware Attacks"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/02\/apt28-uses-microsoft-office-cve-2026.html\">APT28 Uses Microsoft Office CVE-2026-21509 in Espionage-Focused Malware Attacks<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/02\/apt28-uses-microsoft-office-cve-2026.html\">https:\/\/thehackernews.com\/2026\/02\/apt28-uses-microsoft-office-cve-2026.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-02-03 04:12:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><span class=\"p-author\">\ue804<span class=\"author\">Ravie Lakshmanan<\/span>\ue802<span class=\"author\">Feb 03, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Malware<\/span><\/p>\n<p>The Russia-linked state-sponsored threat actor known as <strong>APT28<\/strong> (aka UAC-0001) has been attributed to attacks exploiting a newly disclosed security flaw in Microsoft Office as part of a campaign codenamed Operation Neusploit.<\/p>\n<p>Zscaler ThreatLabz said it observed the hacking group weaponizing the shortcoming on January 29, 2026, in attacks targeting users in Ukraine, Slovakia, and Romania, three days after Microsoft publicly disclosed the existence of the bug.<\/p>\n<p>The vulnerability in question is CVE-2026-21509 (CVSS score: 7.8), a security feature bypass in Microsoft Office that could allow an unauthorized attacker to send a specially crafted Office file and trigger it.<\/p>\n<p>&#8220;Social engineering lures were crafted in both English and localized languages (Romanian, Slovak, and Ukrainian) to target the users in the respective countries,&#8221; security researchers Sudeep Singh and Roy Tay said. &#8220;The threat actor employed server-side evasion techniques, responding with the malicious DLL only when requests originated from the targeted geographic region and included the correct User-Agent HTTP header.&#8221;<\/p>\n<p><img decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg5Ij_-TeqFMEsRFzgRRFzSRlVK6oHCncN_eJ2fkOdsA_1tN9HQbAlEEife2Z2JUt1lPv4st5n9KZP84jGEYY9Up6BQ7QE-N5rs6OhzL5thxGzVxnMx3JH9cGRLi9S5Kl-iV5PgjBeTdkBLnv_inF8UUAo88iqdmgJuPIc_6qiPyUMXwFyZWbZvkZkcRXSw\/s728-e100\/gartner-d.jpg\" width=\"729\" height=\"91\"\/><\/p>\n<p>The attack chains, in a nutshell, entail the exploitation of the security hole by means of a malicious RTF file to deliver two different versions of a dropper, one that&#8217;s designed to drop an Outlook email stealer called MiniDoor, and another, referred to as PixyNetLoader, that&#8217;s responsible for the deployment of a Covenant Grunt implant.<\/p>\n<p>The first dropper acts as a pathway for serving MiniDoor, a C++-based DLL file that steals a user&#8217;s emails in various folders (Inbox, Junk, and Drafts) and forwards them to two hard-coded threat actor email addresses: ahmeclaw2002@outlook[.]com and ahmeclaw@proton[.]me. MiniDoor is assessed to be a stripped-down version of NotDoor (aka GONEPOSTAL), which was documented by S2 Grupo LAB52 in September 2025.<\/p>\n<p>In contrast, the second dropper, i.e., PixyNetLoader, is used to initiate a much more&#8230;<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/02\/apt28-uses-microsoft-office-cve-2026.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>APT28 Uses Microsoft Office CVE-2026-21509 in Espionage-Focused Malware Attacks https:\/\/thehackernews.com\/2026\/02\/apt28-uses-microsoft-office-cve-2026.html Publish Date: 2026-02-03 04:12:00 Source&#8230;<\/p>\n","protected":false},"author":1,"featured_media":209491,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8WToLgQKoSrd-Jg_YD7OJQSJIx2IjJPdhMLYQNTuE9_0bNVo7rwzOdJ0fj0x8oy7-1i4OcXxRbB4nDF502wV5Jwxl5mKPZRpjz5kWijxGRixX2jaewHQHmxGAWVguAFni_muFJNsk610Gaa4JMCCvJMQ7j9kmKgww3U3-z8olchagQGw6cGXxte_4tyPS\/s1700-e365\/office.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24,32,34,27],"class_list":["post-209490","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-malware","tag-threat-actor","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/209490"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=209490"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/209490\/revisions"}],"predecessor-version":[{"id":209492,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/209490\/revisions\/209492"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/209491"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=209490"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=209490"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=209490"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}