INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Fancy Bear APT Continues Global Onslaught

| 2026-04-09 20:50 CRITICAL HIGH
Executive Summary AI-generated
The threat landscape is increasingly complex, with multiple actors and tactics on the rise. Fancy Bear, a cyber-espionage group believed to be operating at the behest of Russian military intelligence, continues its global onslaught. The group has been targeting governments and organizations for years, including in 2016, and has also been linked to US election interference. Recent incidents have highlighted Pawn Storm's adaptability and effectiveness, with malware components known as "Prismex" used to target the defense supply-chain of Ukraine and its allies. This has led to warnings from security vendors about the group's use of social engineering and phishing tactics, as well as sophisticated credential theft campaigns involving critical vulnerabilities. The threat actor remains a significant concern, with multiple reports suggesting Pawn Storm is linked to GRU networks compromised by SOHO routers used for malicious DNS hijacking operations.
Technical Mitigations AI-generated
* Implement a robust security patching strategy to address known vulnerabilities, including Windows zero-days and patched Outlook vulnerabilities. * Use cloud security solutions that include DNS hijacking protection and malware detection to minimize the impact of Pawn Storm's PRISMEX malware on critical infrastructure. * Conduct regular vulnerability assessments and penetration testing to identify potential entry points for Pawn Storm's attacks. * Educate users about spear-phishing tactics, such as phishing emails with malicious attachments or links, and provide training on how to recognize and report suspicious activity. * Implement a multi-factor authentication (MFA) policy that requires strong passwords and two-factor authentication whenever possible to prevent Pawn Storm from gaining unauthorized access.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation NeusploitOperation NeusploitCampaign Targeting UkraineCampaign Targeting Ukraine APT28APT28 Medusa RansomwareMedusa RansomwareDenisDenis CVE-2026-21513CVE-2026-21513 CVE-2023-50224CVE-2023-50224 CVE-2026-21509CVE-2026-21509 CVE-2023-23397CVE-2023-23397
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎April 2022
Russia's Forest Blizzard exploited SOHO routers to gain unauthorized access and steal logins.
target_region Russian Federation
organisation Forest Blizzard Nabs Rafts
organisation SOHO
‎November 2023
Russia's Forest Blizzard exploited multiple Windows vulnerabilities to gain unauthorized access.
target_region Russian Federation
organisation Forest Blizzard Nabs Rafts
organisation SOHO
threat_actor APT28
infrastructure Windows
organisation CVE-2026
organisation Microsoft Office
‎at least 2024
Russia's GRU actors used compromised devices to introduce attacker-controlled DNS resolvers and set up adversary-in-the-middle attacks against encrypted traffic.
‎late February 2025
Threat actors used a Microsoft Shortcut (LNK) exploit to weaponize CVE-2026-21513 as a zero-day vulnerability in Windows.
threat_actor APT28
vulnerability CVE-2026-21513
infrastructure Windows
organisation Akamai
organisation Microsoft Shortcut
organisation VirusTotal
‎late 2025
PrismexStager is assessed to be an expansion of MiniDoor and NotDoor, a Microsoft Outlook backdoor deployed by the hacking group in late 2025.
‎June 2025
Threat actors used COVENANT, an open-source command-and-control framework.
target_region Ukraine
threat_actor APT28
attribution the Computer Emergency Response Team of Ukraine
attribution CERT-UA
‎at least  September 2025
Threat actors used malware to gain unauthorized access to compromised systems.
‎September 2025
APT28, a threat actor linked to Russia's GRU, continues its global onslaught by leveraging various techniques including DNS hijacking networks and exploiting vulnerabilities such as CVE-2023-23397.
threat_actor APT28
organisation CVE-2023-23397
organisation Tor
organisation IP
organisation ClickFix
organisation NATO
organisation Microsoft] Office
organisation National Cyber Security Centre
organisation CVE-2023-50224
organisation API
organisation SMB
organisation NTLM
organisation DNS
organisation Trend Micro's
organisation Calderone
organisation FrostArmada
organisation CAPTCHA
organisation Vishal Agarwal
organisation CTO
organisation Averlon
organisation BreachLock
organisation Omdia
organisation SOC
‎October 2025
The wiper payload used by the COVENANT Grunt APT to target systems and erase files under "%USERPROFILE%" in at least one incident in October 2025.
tactic Wiper
‎January 12, 2026
Threat actors used newly disclosed vulnerabilities to breach targets of interest.
vulnerability CVE-2026-21509
vulnerability CVE-2026-21513
‎January 30, 2026
Russia's 'Fancy Bear' APT used a zero-day vulnerability in Windows to target its exploit.
threat_actor APT28
vulnerability CVE-2026-21513
infrastructure Windows
organisation Akamai
organisation Microsoft Shortcut
organisation VirusTotal
‎February 10, 2026
Russia's Fancy Bear APT group continued its global cyberattack campaign.
‎February 10
Threat actors used a zero-day vulnerability in Windows to exploit CVE-2026-21513, which was uploaded as a Microsoft Shortcut (LNK) on January 30, 2026.
threat_actor APT28
vulnerability CVE-2026-21513
infrastructure Windows
organisation Akamai
organisation Microsoft Shortcut
organisation VirusTotal
‎March 26
Russia's 'Fancy Bear' APT, referred to as Pawn Storm, has been using a collection of malware components known as "Prismex" to target the defense supply-chain of Ukraine and its allies.
target_region Ukraine
target_region Poland
target_region Romania
target_region Slovenia
target_region Slovakia
‎April 3
Russia's Forest Blizzard exploited SOHO routers to gain unauthorized access and steal logins between April 2022 and November 2023.
target_region Russian Federation
organisation Forest Blizzard Nabs Rafts
organisation SOHO
‎Apr 08, 2026
Threat actors used a previously unknown exploit in the Windows operating system to gain unauthorized access to compromised systems.
‎the mid-2000s
Threat actors used stolen data from compromised US government systems to target Russian targets.
target_region Russian Federation
‎2026/04/09
Threat actors used Pawn Storm's old methodologies to target defenders in 2024, which remain effective today.
‎2026/04/09
Russia's 'Fancy Bear' APT continues its global onslaught by deploying a dual-capability malware, PrismexLoader.
threat_actor APT28
organisation Deploys PRISMEX
organisation NATO Allies
organisation NATO
organisation Trend Micro
organisation Fancy Bear
organisation CVE-2026
organisation PrismexLoader
organisation PNG
organisation Zscaler ThreatLabz
organisation Microsoft
organisation MiniDoor
organisation Outlook
organisation PRISMEX
organisation VBA
organisation DLL
‎08, 2026
Threat actors used a previously undisclosed malware suite codenamed PRISMEX to target Ukraine and its allies through spear-phishing campaigns.
threat_actor APT28
source_region Russian Federation
source_region Ukraine
tactic Phishing
organisation Vulnerability / Cloud Security
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Microsoft Office
Affected Product
Intelligence Sources