Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

APT28 Hackers Exploiting Microsoft Office 0-Day in the Wild to Deploy Malware

## APT28 Exploits Microsoft Office Zero-Day Vulnerability

APT28 Exploits Microsoft Office Zero-Day Vulnerability

The advanced persistent threat group APT28 has launched a campaign targeting Central and Eastern Europe by exploiting a zero-day vulnerability in Microsoft Office. The attack utilizes specially crafted Microsoft Rich Text Format (RTF) files to deliver malicious backdoors through a multi-stage infection chain.

This operation, identified as Operation Neusploit, focuses on high-value targets in Ukraine, Slovakia, and Romania. The initial attack vector involves socially engineered emails containing weaponized RTF documents . These messages are customized in multiple languages to increase infection rates.

Once the RTF files are opened, the vulnerability is triggered, allowing arbitrary code execution on the compromised system without user awareness.

Infection Mechanism and Persistence Strategy

The infection chain employs two types of dropper malware designed to deploy varying payloads. The first variant installs MiniDoor, an email-stealing tool that leverages Microsoft Outlook Visual Basic for Applications (VBA). MiniDoor monitors Outlook login events and extracts emails, forwarding them to attacker-controlled addresses.

The attack utilizes specially crafted Microsoft Rich Text Format (RTF) files to deliver malicious backdoors through a multi-stage infection chain.
Brian Shaw · Thehackingpost

Persistence is achieved by altering Windows registry settings to disable Outlook security features and load the malicious macro upon application launch.

CVE ID: CVE-2026-21509 Vulnerability Type: Remote Code Execution Affected Component: Microsoft Office RTF Handler Severity: Critical Patch Date: January 26, 2026

The second dropper variant deploys PixyNetLoader, facilitating the deployment of the Covenant Grunt implant for command-and-control operations. Both variants implement server-side evasion techniques to deliver payloads selectively based on geographic origin and HTTP headers, complicating detection efforts.

Advertisement

Zscaler analysts identified the campaign in January 2026, attributing it to APT28 due to overlaps in tools and techniques with known operations. Active exploitation was observed on January 29, 2026, shortly after Microsoft issued an emergency update for the vulnerability.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories