APT28 exploits fresh Office flaw against targets in Ukraine and the EU
Microsoft released an out-of-band update last week for CVE-2026-21509 in Office, noting that the flaw was under active exploitation. Ukraine's CERT-UA and Zscaler ThreatLabz now both confirm exploitation in a campaign aimed at organisations in Ukraine and EU countries. The observed samples led to two different payloads: a macro-based Outlook email stealer called MiniDoor, and a Grunt implant associated with the Covenant C2 framework. Both sources attribute the campaign to the Russian state-sponsored actor UAC-001/APT28.
What this means for your organisation
Norwegian organisations in defence, energy, transport and public administration fall within this actor's geographic and thematic scope. An email stealer in Outlook means the content of your correspondence is the objective, not merely the access. For a management team, the question is therefore not only whether the machine was cleaned, but what information may have left the building in the meantime.
Berigo recommends
- Deploy the CVE-2026-21509 update across all Office installations, paying particular attention to older versions.
- Check Outlook for unexpected macros and rules, and remove anything not approved.
- Run the indicators from CERT-UA and Zscaler against your existing logs, not only against future traffic.
- Review your incident plan for the scenario where email content has been exfiltrated, including notifying the parties in that correspondence.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch