HomeSecurityAPT28 targets Ukraine with PRISMEX malware

APT28 targets Ukraine with PRISMEX malware

Russian hackers APT28 have been linked to a new spear-phishing targeting Ukraine and its allies for the development of the new PRISMEX malware.

APT28 PRISMEX

“ PRISMEX combines advanced steganography, component object model (COM) hijacking, and abuse of legitimate cloud services for command-and-control ,” Trend Micro researchers Feike Hacquebord and Hiroyuki Kakara said in a technical report. The campaign is believed to have been active since at least September 2025.

Malicious activity has targeted various sectors in Ukraine, including central executive bodies, hydrometeorology, defense, emergency services, rail logistics (Poland), shipping and transport (Romania, Slovenia, Turkey), logistical support partners involved in ammunition (Slovakia, Czech Republic), and military and NATO partners.

See also: FBI Disrupts APT28's DNS Hijacking Network

The campaign is notable for its rapid exploitation of newly disclosed vulnerabilities, such as CVE-2026-21509 and CVE-2026-21513. The vulnerabilities are used to compromise targets of interest, with infrastructure preparation observed on January 12, 2026, exactly two weeks before the first bug was publicly disclosed.

In late February, Akamai also revealed that APT28 may have exploited CVE-2026-21513 as a zero-day, based on a Microsoft Shortcut (LNK) exploit uploaded to VirusTotal on January 30, 2026 (long before Microsoft released a fix on February 10, 2026).

This zero-day exploit indicates that the threat actor was aware of the vulnerabilities before they were disclosed by Microsoft.

An interesting finding by the researchers is the common domain “wellnesscaremed[.]com.” This, combined with the timing of the two exploits, may mean that threat actors are linking CVE-2026-21513 and CVE-2026-21509 in a sophisticated two-stage attack chain.

See also: APT28 exploits SOHO routers in DNS Hijacking campaign

APT28 targets Ukraine with PRISMEX malware

“The first vulnerability (CVE-2026-21509) forces the victim’s system to retrieve a malicious .LNK file, which then exploits the second vulnerability (CVE-2026-21513) to bypass security features and execute payloads without user warnings,” Trend Micro believes.

What malware is APT28 using in the new campaign?

The attacks result in the deployment of either MiniDoor, an Outlook email stealer, or a collection of interconnected malware components collectively known as PRISMEX. Named for its use of a steganography technique to hide payloads within image files. These include:

– PrismexSheet, a malicious Excel dropper with VBA macros that extracts payloads embedded within the file using steganography. It establishes persistence via COM hijacking and displays a misleading document related to drone inventory lists and drone prices after the macros are activated.

– PrismexDrop, a native dropper that prepares the environment for subsequent exploitation and uses scheduled tasks and COM DLL hijacking for persistence.

– PrismexLoader (also known as PixyNetLoader), a proxy DLL that extracts the next stage .NET payload scattered across a PNG file structure (“SplashScreen.png”) using a special “Bit Plane Round Robin” algorithm. It executes it entirely in memory.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

– PrismexStager, a COVENANT Grunt implant that abuses the Filen.io cloud storage for C2.

It is worth noting that some aspects of the campaign were previously documented by Zscaler ThreatLabz (Operation Neusploit).

See also: Storm-1175: Zero-day exploit for Medusa ransomware deployment

APT28's use of COVENANT was first noted by the Ukrainian Computer Emergency Response Team (CERT-UA) in June 2025. PrismexStager is believed to be an extension of MiniDoor and NotDoor (also known as GONEPOSTAL), a Microsoft Outlook backdoor developed by the hacking group in late 2025.

APT28 targets Ukraine with PRISMEX malware

In at least one incident in October 2025, the COVENANT Grunt payload was found to facilitate not only intelligence gathering but also execute a destructive wiper command that deletes all files in the “%USERPROFILE%” directory. This dual capability suggests that these campaigns could have been designed for espionage and sabotage.

“This operation demonstrates that APT28 remains one of the most aggressive Russian-aligned groups,” Trend Micro said. “The targeting pattern reveals a strategic intent to compromise the supply chain and operational planning capabilities of Ukraine and its NATO partners.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS