A serious cyber attack has recently been discovered against Ukrainian government organizations and European Union institutions. The Russian hacker group known as APT28 (also called Fancy Bear or UAC-0001) has exploited a security vulnerability in Microsoft Office to infiltrate victims’ systems and steal sensitive information.
The attack, which began between January 27 and 29, 2026, used a “spear-phishing” technique, which involves sending targeted emails containing malicious documents in RTF or DOC format. These files exploited a security vulnerability identified as CVE-2026-21509, which allowed bypassing Microsoft Office protections. Once the document was opened, a complex infection chain was activated that installed backdoors called MiniDoor and NotDoor on compromised computers. The infection process included several technical phases, including the use of VBA macros in Outlook, malicious DLL components, and scheduled tasks in the operating system to ensure persistence of access.
This breach is particularly concerning because it specifically targeted Ukrainian government agencies and European Union organizations, with a focus on Central and Eastern Europe. The potential impact includes theft of confidential emails (which were sent to predefined addresses controlled by the attackers) and the creation of permanent access points for future espionage operations. The timing of the attack is also significant, occurring just a few hours or days after Microsoft disclosed the existence of the vulnerability.
To protect against this type of threat, organizations should immediately install all security patches released by Microsoft, particularly those related to vulnerability CVE-2026-21509. It is also advisable to strengthen employee training on recognizing suspicious emails, implement advanced security solutions that can detect anomalous system behavior, and consider using sandboxing tools for opening attachments from external sources.
- Key points to remember:
- State-sponsored cyber attacks are becoming increasingly sophisticated and targeted towards strategic objectives
- Timely system updates are essential to protect against known vulnerabilities
- User awareness remains one of the first lines of defense against phishing attacks, even the most elaborate ones
Sources:
https://www.zscaler.com/it/blogs/security-research/apt28-leverages-cve-2026-21509-operation-neusploit
https://www.theregister.com/2026/02/02/russialinked_apt28_microsoft_office_bug/
https://cyberpress.org/microsoft-office-zero-day-to-deliver-malware/
https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-recently-patched-microsoft-office-bug-in-attacks/amp/
Source: Security Affairs