INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Microsoft Office CVE-2026-21509 Exploit Used in Fancy Bear Attacks

| 2026-02-03 10:33 CRITICAL HIGH
Executive Summary AI-generated
The vulnerability, CVE-2026-21509, has been exploited by Russian cybercriminals linked to the Computer Emergency Response Team of Ukraine (CERT-UA) just days after Microsoft released a security patch. The malicious use of this bug is part of ongoing cyber-espionage campaigns against government bodies and European entities. CERT-UA had previously detected similar activity in June 2025, when groups like Ciberdelincuentes rusos exploded talks to distribute other implants such as BeardShell and SlimAgent against Ukrainian government organizations. This vulnerability affects multiple versions of Microsoft Office and was initially catalogued as a zero-day before an official update.
Technical Mitigations AI-generated
* Keep software and operating systems up to date: Ensure that all Microsoft Office applications, as well as other critical system components, are running with the latest security patches. This will help prevent exploitation of known vulnerabilities like CVE-2026-21509. * Use strong antivirus protection: Install and regularly update antivirus software to detect and block malicious files, including those used in APT28's attacks. * Be cautious when opening attachments from unknown sources: Avoid opening documents or emails that you don't recognize as legitimate. If in doubt, contact the sender to verify the authenticity of the message. * Use secure communication channels: When communicating with government agencies or other entities, use secure protocols like Signal or encrypted email services (e.g., ProtonMail) instead of cloud-based services for command and control communications (C2). * Monitor system logs and behavior: Regularly review system logs to detect any suspicious activity. Also, monitor system performance and behavior to identify potential security threats early on. * Implement a firewall and network segmentation: Configure firewalls and segment your network to limit access to critical systems and prevent lateral movement in case of an attack. Note: These mitigations are not foolproof and should be used as part of a comprehensive cybersecurity strategy.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
APT28APT28 SofacySofacy CVE-2026-21509CVE-2026-21509
Target & Sectors
EUROPE EUROPE FIVE_EYES FIVE_EYES healthcarehealthcare mediamedia educationeducation legallegal governmentgovernment retailretail manufacturingmanufacturing financefinance
Incident Timeline
June 2025
Threat actors used Microsoft Office to target Ukrainian government organizations.
attribution CERT-UA
industry Government
target_region Ukraine
attribution Signal
attribution BeardShell
attribution SlimAgent
late January 2026
Threat actors used a recently patched Microsoft Office vulnerability to exploit it in three additional documents targeting organizations in EU countries.
January 26
Threat actors exploited a recently patched vulnerability in Microsoft Office.
organisation Microsoft
infrastructure Microsoft Office
January 26, 2026
Threat actors exploited a recently patched vulnerability in Microsoft Office.
infrastructure Microsoft Office
vulnerability CVSS score of 7.8
infrastructure 7.8
January 27, 2026
Threat actors exploited a recently patched vulnerability in Microsoft Office.
vulnerability CVE-2026-21509
infrastructure Microsoft Office
January 27
Threat actors exploited a recently patched vulnerability in Microsoft Office.
January 29
Threat actors exploited a previously unknown vulnerability in Microsoft Office before its official disclosure.
attribution CVE-2026-21509
attribution CERT-UA
attribution DOC
February 2
Threat actors exploited a recently patched vulnerability in Microsoft Office.
attribution CERT-UA
target_region Ukraine
attribution the Computer Emergency Response Team of
2016, 2019
Threat actors exploited a recently patched vulnerability in Microsoft Office 2016 and its variants.
vulnerability CVE-2026-21509
organisation Microsoft
infrastructure 7.8
infrastructure Microsoft 365
general_metric 365 Microsoft
infrastructure Microsoft Office 2016
vulnerability CVSS 3.1
infrastructure 3.1
organisation LTSC 2021
organisation LTSC 2024
general_metric 3.1 score
general_metric 2021 LTSC
general_metric 2024 LTSC
2026-02-03
Threat actors used a recently disclosed vulnerability in Microsoft Office to conduct cyber-attacks against Ukrainian and EU organizations.
organisation Microsoft Office
threat_actor APT28
organisation el contrabando de armas transnacionales
organisation el usuario.
organisation un
organisation de funciones de seguridad
organisation de Office
organisation parcheada de Microsoft Office
organisation Microsoft 365
organisation Object Linking and
organisation OLE
infrastructure Microsoft Office 2016
infrastructure Microsoft Office 2019
organisation Microsoft Office LTSC
organisation EU Cyber-Attacks
organisation EU
organisation Operación Phantom Net Voxel
data_breach 2025 uso era destacado por septiembre de
organisation Trellix
organisation Oficina de Microsoft 1
organisation día dentro de las 24
organisation el mantenimiento
organisation ZTNA
organisation DNS Protection
organisation CSPM
organisation Entre
organisation de código de shell
organisation PNG
organisation DLL
infrastructure Windows
organisation Zscaler ThreatLabz
organisation el grupo de piratería
organisation Ucrania, Eslovaquia
organisation días después de que
organisation Microsoft
organisation Los señuelos de ingeniería
organisation dijeron los investigadores de seguridad
organisation El actor de la amenaza empleó
organisation originaron de la región
organisation el encabezado
organisation implican la
organisation del agujero de seguridad
organisation RTF
organisation MiniDoor
organisation vía
organisation correos
organisation electrónicos de un
organisation Inbox
organisation Drafts
organisation electrónico de un
organisation utiliza
organisation cadena de ataque mucho más elaborada que
organisation el establecimiento de la persistencia
organisation el host utilizando Secuestramiento de objetos COM
organisation analizar el código de shell
organisation el cargador
organisation El malware
organisation El código extraído
organisation Grunt
organisation el marco de código
organisation VBA
organisation cadena de ataque idéntica
organisation el despliegue
organisation cadena de infección
organisation el tráfico
organisation Esto
organisation de un Microsoft Shortcut (
organisation LNK
organisation el backdoor BEARDSHELL
organisation utilizando cargas de pago cifradas
organisation inyección de procesos
organisation European Union COREPER
organisation Performance Cookies
organisation Licenses & Accounts *
organisation Sophos Home Open
organisation XDR - Extended
organisation Next-Gen SIEM *
organisation Back Identity
organisation ITDR - Identity
organisation NGFW
organisation IR - Incident
organisation ← Back Advisory
organisation Back Professional
organisation NIS2
organisation ← Back Trust
organisation Digital
victims 600,000 customers
organisation Digital Operational Resilience Act
organisation Sophos
organisation TAM
organisation Sophos Academy
organisation Counter Threat Unit Research Team
organisation Copy linkLink Copied
organisation Office
organisation Calculator Services
Tactical Metrics
Metrics
infrastructure
​Microsoft Office
Affected Product
Metrics
data_breach
2,025
Uso Era Destacado Por Septiembre De
Metrics
infrastructure
​7.8
Software Version
Metrics
infrastructure
​Microsoft 365
Affected Product
Metrics
infrastructure
​Microsoft Office 2016
Affected Product
Metrics
infrastructure
​Microsoft Office 2019
Affected Product
Metrics
victims
600,000
Customers
Metrics
infrastructure
​3.1
Software Version
Metrics
infrastructure
​Windows
Affected Product