APT28 weaponizes Office flaw in Neusploit to deploy Covenant Grunt

1 min read
Source: The Hacker News
APT28 weaponizes Office flaw in Neusploit to deploy Covenant Grunt
Photo: The Hacker News
TL;DR Summary

Russia-linked APT28 is exploiting CVE-2026-21509 in Microsoft Office as part of Operation Neusploit, delivering two droppers through malicious RTFs: MiniDoor, an Outlook email stealer, and PixyNetLoader, which loads Covenant Grunt via a steganography-delivered shellcode loader; attacks target Ukraine, Slovakia, and Romania with region- and UA-based checks, and show overlaps with earlier Phantom Net Voxel activity.

Share this article

Reading Insights

Total Reads

1

Unique Readers

7

Time Saved

3 min

vs 4 min read

Condensed

92%

67855 words

Want the full story? Read the original article

Read on The Hacker News