APT28 Hackers Exploiting Microsoft Office 0-Day in the Wild to Deploy Malware
## APT28 Exploits Microsoft Office Zero-Day Vulnerability
APT28 Exploits Microsoft Office Zero-Day Vulnerability
The advanced persistent threat group APT28 has launched a campaign targeting Central and Eastern Europe by exploiting a zero-day vulnerability in Microsoft Office. The attack utilizes specially crafted Microsoft Rich Text Format (RTF) files to deliver malicious backdoors through a multi-stage infection chain.
This operation, identified as Operation Neusploit, focuses on high-value targets in Ukraine, Slovakia, and Romania. The initial attack vector involves socially engineered emails containing weaponized RTF documents . These messages are customized in multiple languages to increase infection rates.
Once the RTF files are opened, the vulnerability is triggered, allowing arbitrary code execution on the compromised system without user awareness.
Infection Mechanism and Persistence Strategy
The infection chain employs two types of dropper malware designed to deploy varying payloads. The first variant installs MiniDoor, an email-stealing tool that leverages Microsoft Outlook Visual Basic for Applications (VBA). MiniDoor monitors Outlook login events and extracts emails, forwarding them to attacker-controlled addresses.
The attack utilizes specially crafted Microsoft Rich Text Format (RTF) files to deliver malicious backdoors through a multi-stage infection chain.
Persistence is achieved by altering Windows registry settings to disable Outlook security features and load the malicious macro upon application launch.
CVE ID: CVE-2026-21509 Vulnerability Type: Remote Code Execution Affected Component: Microsoft Office RTF Handler Severity: Critical Patch Date: January 26, 2026
The second dropper variant deploys PixyNetLoader, facilitating the deployment of the Covenant Grunt implant for command-and-control operations. Both variants implement server-side evasion techniques to deliver payloads selectively based on geographic origin and HTTP headers, complicating detection efforts.
Zscaler analysts identified the campaign in January 2026, attributing it to APT28 due to overlaps in tools and techniques with known operations. Active exploitation was observed on January 29, 2026, shortly after Microsoft issued an emergency update for the vulnerability.
Based on reporting by Cyber Security News.
