INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Microsoft Office Zero-Day Exploit Used by APT28 Hackers

| 2026-03-10 10:00 CRITICAL HIGH
Executive Summary AI-generated
The Russian state-sponsored APT28 threat group, known for its high-end espionage operations and custom variants of open-source tools like Covenant post-exploitation framework, has been gaining long-term capabilities since 2024. Researchers at cybersecurity company ESET have identified two new malware families: BeardShell and a heavily modified version of the Covenant .NET post-exploitation framework. These attacks have targeted central executive bodies in Ukraine, exploiting CVE-2026-21509 vulnerability in Microsoft Office via malicious DOC files. The group has paired these malware with a custom variant of the open-source tool Icedrive for command-and-control communication and leverages legitimate cloud storage services like Icedrive to execute PowerShell commands in a .NET runtime environment. This dual-implant approach enables long-term surveillance, making APT28's advanced malware development team return to activity after a period of dormancy.
Technical Mitigations AI-generated
* Use of secure and up-to-date software: Ensure that all systems, applications, and services are running with the latest security patches and updates to prevent exploitation of known vulnerabilities. * Implement robust access controls and authentication: Use strong passwords, multi-factor authentication, and role-based access control (RBAC) to limit user privileges and ensure only authorized personnel can access sensitive data or systems. * Monitor for suspicious activity and anomalies: Regularly scan logs and system performance metrics for signs of unusual behavior, such as unexpected changes in network traffic patterns or unauthorized access attempts. Implement alerting mechanisms to notify IT teams promptly if any suspicious activity is detected. * Use anti-malware software with advanced threat detection capabilities: Install and regularly update anti-malware software that includes features like sandboxing, behavioral analysis, and rootkit detection to detect and prevent APT28-style malware infections. * Keep operating systems and applications up-to-date with the latest security patches: Ensure all operating systems (OS) and applications are running with the latest security updates, including Microsoft Office, as soon as they become available.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
APT28APT28 SednitSednit CVE-2026-21509CVE-2026-21509
Target & Sectors
UA
governmentgovernment
Incident Timeline
April 2024
Threat actors used BeardShell to deploy a customized variant of the Covenant open-source tool in attacks against central executive bodies of Ukraine.
source_region Russian Federation
organisation ESET
organisation Microsoft Office
organisation DOC
organisation BeardShell
June 2025
Threat actors used a customized variant of the Covenant open-source tool, paired with SlimAgent and heavily modified to target .NET runtime environments.
attribution CERT-UA
attribution SlimAgent
tactic T1059.001 - PowerShell
July 2025
APT28 hackers deployed a customized variant of the Covenant open-source tool.
organisation Filen
threat_actor APT28
organisation Koofr
organisation BearShell
organisation The Red Report 2026
2026-03-10
APT28 hackers deploy customized variant of Covenant open-source tool.
target_region Ukraine
organisation Microsoft Office
threat_actor APT28
organisation día de Microsoft Office
organisation los responsables de incidentes
infrastructure Windows
organisation DLL
organisation el último
organisation Un
organisation fue abordado
organisation Ucrania
organisation el día después de que
organisation Microsoft
organisation DOC
organisation Office
organisation La mayoría de los usuarios
organisation El resultado
organisation el despliegue del marco de post-explotación
organisation PACANTE
the 2010s
BeardShell, a customized variant of the open-source tool Covenant, was used by APT28 hackers in the 2010s to deploy network-pivoting capabilities.
threat_actor APT28
Tactical Metrics
Metrics
infrastructure
​Microsoft Office
Affected Product
Metrics
infrastructure
​Windows
Affected Product
Intelligence Sources
The Register - Cybercrime 2026-02-02