APT28 Hackers Exploit Microsoft Office Vulnerability to Target Government Agencies
## Cybersecurity: Recent Cyberattack Campaigns by APT28
Cybersecurity: Recent Cyberattack Campaigns by APT28
Russian state-sponsored hackers, identified as APT28 or Fancy Bear, have initiated a new series of cyberattacks targeting governmental and military entities across Europe.
In a campaign observed in late January 2026, these attacks focus on extracting sensitive information from maritime and transport agencies in countries such as Poland, Greece, and Ukraine.
The attack methodology involves spear-phishing emails designed to mimic official communications. Between January 28 and 30, 2026, the hackers dispatched emails impersonating government agencies.
The infiltration leverages a vulnerability in Microsoft Office, CVE-2026-21509, allowing unauthorized access to computer systems without user interaction.
Common phishing themes include alerts about weapons smuggling, military training invitations, diplomatic requests from NATO/EU, and urgent weather alerts.
An error in the email signature, "Boarder Police" instead of "Border Police," indicated potential non-native English speakers behind the attacks.
The attack methodology involves spear-phishing emails designed to mimic official communications.
Silent Break-In: Exploiting CVE-2026-21509
The campaign's primary threat is the exploitation of CVE-2026-21509, a vulnerability in Microsoft Office's handling of "OLE" objects.
The attacks bypass typical security measures, such as enabling macros, by using a sophisticated PNG decoder to download malware via WebDAV, avoiding standard security alerts.
APT28 employs various malicious tools, including "SimpleLoader" for malware persistence and "BeardShell," a C++ program, to evade antivirus detection.
"BeardShell" is concealed within PNG image files, misleading security software. The "Covenant" framework is used for command issuance via a legitimate cloud storage service, filen.io .
APT28 also uses "NotDoor," a backdoor within Microsoft Outlook's email system. It creates hidden rules to monitor and forward specific emails to the attackers.
The campaign highlights APT28’s rapid exploitation of emerging vulnerabilities.
Organizations are advised to update Microsoft Office to address CVE-2026-21509 and monitor network traffic for anomalies related to filen.io and "NotDoor" configurations in Outlook.
Based on reporting by GBHackers.
