Russian hackers APT28 have been linked to a new spear-phishing targeting Ukraine and its allies for the development of the new PRISMEX malware.

“ PRISMEX combines advanced steganography, component object model (COM) hijacking, and abuse of legitimate cloud services for command-and-control ,” Trend Micro researchers Feike Hacquebord and Hiroyuki Kakara said in a technical report. The campaign is believed to have been active since at least September 2025.
Malicious activity has targeted various sectors in Ukraine, including central executive bodies, hydrometeorology, defense, emergency services, rail logistics (Poland), shipping and transport (Romania, Slovenia, Turkey), logistical support partners involved in ammunition (Slovakia, Czech Republic), and military and NATO partners.
See also: FBI Disrupts APT28's DNS Hijacking Network
The campaign is notable for its rapid exploitation of newly disclosed vulnerabilities, such as CVE-2026-21509 and CVE-2026-21513. The vulnerabilities are used to compromise targets of interest, with infrastructure preparation observed on January 12, 2026, exactly two weeks before the first bug was publicly disclosed.
In late February, Akamai also revealed that APT28 may have exploited CVE-2026-21513 as a zero-day, based on a Microsoft Shortcut (LNK) exploit uploaded to VirusTotal on January 30, 2026 (long before Microsoft released a fix on February 10, 2026).
This zero-day exploit indicates that the threat actor was aware of the vulnerabilities before they were disclosed by Microsoft.
An interesting finding by the researchers is the common domain “wellnesscaremed[.]com.” This, combined with the timing of the two exploits, may mean that threat actors are linking CVE-2026-21513 and CVE-2026-21509 in a sophisticated two-stage attack chain.
See also: APT28 exploits SOHO routers in DNS Hijacking campaign

“The first vulnerability (CVE-2026-21509) forces the victim’s system to retrieve a malicious .LNK file, which then exploits the second vulnerability (CVE-2026-21513) to bypass security features and execute payloads without user warnings,” Trend Micro believes.
What malware is APT28 using in the new campaign?
The attacks result in the deployment of either MiniDoor, an Outlook email stealer, or a collection of interconnected malware components collectively known as PRISMEX. Named for its use of a steganography technique to hide payloads within image files. These include:
– PrismexSheet, a malicious Excel dropper with VBA macros that extracts payloads embedded within the file using steganography. It establishes persistence via COM hijacking and displays a misleading document related to drone inventory lists and drone prices after the macros are activated.
– PrismexDrop, a native dropper that prepares the environment for subsequent exploitation and uses scheduled tasks and COM DLL hijacking for persistence.
– PrismexLoader (also known as PixyNetLoader), a proxy DLL that extracts the next stage .NET payload scattered across a PNG file structure (“SplashScreen.png”) using a special “Bit Plane Round Robin” algorithm. It executes it entirely in memory.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
– PrismexStager, a COVENANT Grunt implant that abuses the Filen.io cloud storage for C2.
It is worth noting that some aspects of the campaign were previously documented by Zscaler ThreatLabz (Operation Neusploit).
See also: Storm-1175: Zero-day exploit for Medusa ransomware deployment
APT28's use of COVENANT was first noted by the Ukrainian Computer Emergency Response Team (CERT-UA) in June 2025. PrismexStager is believed to be an extension of MiniDoor and NotDoor (also known as GONEPOSTAL), a Microsoft Outlook backdoor developed by the hacking group in late 2025.

In at least one incident in October 2025, the COVENANT Grunt payload was found to facilitate not only intelligence gathering but also execute a destructive wiper command that deletes all files in the “%USERPROFILE%” directory. This dual capability suggests that these campaigns could have been designed for espionage and sabotage.
“This operation demonstrates that APT28 remains one of the most aggressive Russian-aligned groups,” Trend Micro said. “The targeting pattern reveals a strategic intent to compromise the supply chain and operational planning capabilities of Ukraine and its NATO partners.”
