Microsoft releases urgent Office patch. Russian-state hackers pounce.

Date:

Share:



Russian-state hackers wasted no time exploiting a critical Microsoft Office vulnerability that allowed them to compromise the devices inside diplomatic, maritime, and transport organizations in more than half a dozen countries, researchers said Wednesday.

The threat group, tracked under names including APT28, Fancy Bear, Sednit, Forest Blizzard, and Sofacy, pounced on the vulnerability, tracked as CVE-2026-21509, less than 48 hours after Microsoft released an urgent, unscheduled security update late last month, the researchers said. After reverse-engineering the patch, group members wrote an advanced exploit that installed one of two never-before-seen backdoor implants.

Stealth, speed, and precision

The entire campaign was designed to make the compromise undetectable to endpoint protection. Besides being novel, the exploits and payloads were encrypted and ran in memory, making their malice hard to spot. The initial infection vector came from previously compromised government accounts from multiple countries and were likely familiar to the targeted email holders. Command and control channels were hosted in legitimate cloud services that are typically allow-listed inside sensitive networks.

“The use of CVE-2026-21509 demonstrates how quickly state-aligned actors can weaponize new vulnerabilities, shrinking the window for defenders to patch critical systems,” the researchers, with security firm Trellix, wrote. “The campaign’s modular infection chain—from initial phish to in-memory backdoor to secondary implants was carefully designed to leverage trusted channels (HTTPS to cloud services, legitimate email flows) and fileless techniques to hide in plain sight.”

The 72-hour spear phishing campaign began January 28 and delivered at least 29 distinct email lures to organizations in nine countries, primarily in Eastern Europe. Trellix named eight of them: Poland, Slovenia, Turkey, Greece, the UAE, Ukraine, Romania, and Bolivia. Organizations targeted were defense ministries (40 percent), transportation/logistics operators (35 percent), and diplomatic entities (25 percent).



Source link

━ more like this

Israel orders military to prepare for possible Iran conflict as US talks stall – London Business News | Londonlovesbusiness.com

Israel’s military chief has ordered the armed forces to step up readiness for a possible escalation with Iran, according to Israeli media reports,...

The smart home was supposed to be open, but it’s becoming a toll booth

I grew up thinking that paying for a product meant getting the product. A laptop came with its features. A car came with...

Trump warns Iran will be ‘blown to hell’ if they attack US Navy in the Strait of Hormuz – London Business News | Londonlovesbusiness.com

Donald Trump has warned that the United States would respond “severely” if Iran attacks ships in the Strait of Hormuz, amid escalating tensions...

Cartlidge accuses Labour of starving defence while boosting welfare spending – London Business News | Londonlovesbusiness.com

Tory MP James Cartlidge has criticised the Labour government for “prioritising welfare spending over defence spending.” The Conservative Shadow Defence Secretary made this...

Whitehall brings back war readiness planning in face of growing global tensions – London Business News | Londonlovesbusiness.com

Britain is reviving Cold War-era contingency planning to prepare the country for a major conflict, as senior military figures warn that the risk...
spot_img