One of the most dangerous and rapidly evolving cyber threats in recent years is in full swing, with the UAC-0001, known internationally as APT28, actively exploiting a critical zero-day vulnerability in Microsoft Office. The group, which is linked to Russian state interests, is using the security gap for targeted attacks against Ukrainian government agencies as well as organizations in European Union countries.

The vulnerability, codenamed CVE-2026-21509, was officially disclosed by Microsoft on January 26, 2026, accompanied by a clear warning that it was already being actively exploited. What was worrying was not only its severity, but also the speed with which it was transformed into an operational attack tool.
From revelation to attack within 24 hours
Within less than 24 hours of Microsoft's publication, threat actors had already incorporated the exploit into real campaigns. On January 27, 2026, security researchers discovered a malicious Word file titled “Consultation_Topics_Ukraine(Final).doc”that contained a working exploit for CVE-2026-21509.
See also: This distinctive Windows RAT conducts live chats with its operators
The content of the document was not accidental. It referred to consultations of the EU Permanent Representatives Committee (COREPER) on Ukraine, exploiting current events and geopolitical interest as a tool for social engineering. A few days later, on January 29, CERT-UA uncovered a wider phishing campaign with documents pretending to be official weather reports from the Ukrainian Hydrometeorological Center.

Targeted attacks on government agencies
The campaign was clearly targeted. More than 60 email addresses received the malicious messages, the vast majority belonging to central executive bodies of Ukraine. This confirms that this is not a massive, indiscriminate attack, but state-level cyber espionage, with a clear political and strategic dimension.
How the chain of infection works
When the victim opens the infected document in Microsoft Office, the exploit is activated, which establishes a connection to the attacker's infrastructure via the WebDAV. It then downloads a shortcut file containing executable code and installs multiple malicious components on the system.
These include files such as EhStoreShell.dll and SplashScreen.png, which embed shellcode. The attack continues with COM hijacking, by modifying entries in the Windows registry, and creating a scheduled task called “OneDriveHealth” to maintain the malware’s presence on the system.
See also: Chrome extensions abuse links and steal access to ChatGPT
COVENANT and abuse of legitimate cloud services
The final payload of the attack is COVENANT, a powerful and flexible post-exploitation framework that allows for complete control of the system. Particularly worrying is the choice of Filen (filen.io), a legitimate cloud storage service, for command-and-control communications.
In this way, the malicious traffic is “lost” within normal cloud activity, making detection much more difficult for traditional security systems. Researchers also identified additional malicious documents targeting EU countries, confirming the expansion of the campaign.

Speed and operational maturity
In at least one case, attackers registered attack infrastructure domains on the same day the attack took place, demonstrating an extremely high level of preparedness and operational speed, typical of APT teams with significant resources and experience.
See also: Notepad++: Update mechanism breached to distribute malware
Warnings and immediate defensive measures
CERT -UA warns that exploitation attempts are expected to increase as many organizations are unable to promptly apply updates due to slow patching cycles or compatibility limitations. It is recommended to immediately implement the protection measures recommended by Microsoft through the registry, monitor suspicious connections to FileCloud services, and block known indicators of compromise.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
At the same time, users are urged to be extremely wary of unsolicited Office documents, especially when they relate to geopolitical, administrative or “urgent” matters. This campaign proves once again that, in modern cyberwarfare, speed of reaction is as critical as technology.
