Russian hackers targeting European maritime and transport orgs using Microsoft Office exploit
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-21509 | Local Security Feature Bypass in Microsoft Office Under Active Exploitation CVE-2026-21509 is a security feature bypass in Microsoft Office caused by reliance on untrusted input when making a security decision (CWE-807): Office trusts attacker-controlled data when deciding whether a protection applies, allowing an unauthorized local attacker to bypass that security feature. Exploitation is local and requires user interaction (per the CVSS vector), most plausibly by getting a user to open a crafted file or document, and the flaw carries high confidentiality, integrity, and availability impact. Anyone running Microsoft Office, Microsoft 365 Apps, or Office Long Term Servicing Channel is in scope, giving the flaw a potential audience in the hundreds of millions of seats. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-26, Microsoft issued an emergency patch, and headlines attribute in-the-wild use to Russian state hackers targeting Ukrainian and EU organizations, including the maritime and transport sectors (a related APT28 campaign was tied to a separate Office/MSHTML 0-day, CVE-2026-21513). EPSS estimates a 72.6% probability of exploitation within the next 30 days (99th percentile). Do: Apply Microsoft's emergency Office update and the follow-on February 2026 Patch Tuesday fixes across Microsoft 365 Apps, Office, and Office LTSC, checking Microsoft's advisory for the exact affected builds since no version ranges are given in the source data. Given the KEV listing, federal agencies must patch per CISA BOD 22-01 timelines (or follow cloud-service guidance). Hunt for exploitation per vendor guidance — headlines report Russian state use against EU/Ukrainian and maritime/transport targets — and prioritize endpoints where users open untrusted files. | 7.8 | 73% | KEV |
| masshundreds of millions of users/devices (Office and Microsoft 365 Apps have a global installed base on the order of 10^8+ seats) |
Full article450 words · extracted from therecord.media · click to collapse
Researchers have uncovered additional cyberattacks carried out by Russian state-linked hackers exploiting a Microsoft Office vulnerability as part of what they described as a “sophisticated espionage campaign.” The activity has been linked to APT28, or Fancy Bear, a Kremlin-backed hacking group that has targeted Ukraine and NATO-aligned countries for more than two decades. Earlier this week, Ukraine’s computer emergency response team, CERT-UA, and cybersecurity firm Zscaler reported attacks by the group via the same vulnerability against Ukrainian government agencies and public sector organizations in Slovakia and Romania. In a report released Wednesday, researchers at the cybersecurity firm Trellix said they observed broader APT28 activity targeting maritime, transportation and diplomatic entities in countries including Poland, Slovenia, Turkey, Greece and the United Arab Emirates. According to the report, the attacks were part of a “concentrated” 72-hour spearphishing campaign that sent at least 29 distinct emails across nine Eastern European countries. The hackers exploited a newly disclosed Microsoft Office vulnerability, tracked as CVE-2026-21509, shortly after Microsoft revealed the flaw in late January. The campaign began with phishing emails carrying malicious Office documents that triggered the exploit automatically, without requiring user interaction, Trellix said. The messages were sent from compromised government email accounts in several countries, including Romania, Bolivia and Ukraine. Trellix said the attackers used geopolitically themed lures such as weapons-smuggling alerts, NATO and European Union diplomatic invitations, military training notices and emergency weather bulletins. The attached documents were designed to resemble legitimate government correspondence and may have been based on previously stolen material. Once opened, the files deployed a series of tools, including MiniDoor malware designed to steal email data and PixyNetLoader, which ultimately installed a Covenant backdoor on infected systems, the report said. The campaign also made extensive use of legitimate cloud services to obscure malicious activity. Trellix said APT28 used the cloud storage platform Filen as a command-and-control channel, allowing the malware to blend in with normal internet traffic. The hacker group has stepped up operations against Ukraine and its European allies since Russia’s full-scale invasion in 2022 and has a history of rapidly exploiting newly disclosed Office vulnerabilities, often becoming one of the first groups to use them in real-world attacks, according to researchers. “The use of CVE-2026-21509 demonstrates how quickly state-aligned actors can weaponize new vulnerabilities, shrinking the window for defenders to patch critical systems,” Trellix said.
No previous article
No new articles
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/russian-hackers-microsoft-office-europe