Vulnerabilities
APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies
Cyber RTApril 9, 20263 min read

APT28, a Russian threat actor, has launched a spear-phishing campaign targeting Ukraine and its allies, deploying a new malware suite called PRISMEX. This campaign exploits vulnerabilities CVE-2026-21509 and CVE-2026-21513, using steganography and COM hijacking. Targeting sectors like defense and logistics, it aims for espionage and sabotage. The campaign highlights APT28's strategic focus on disrupting Ukraine's supply chains and operational capabilities.
The Russian threat actor group APT28, also known as Forest Blizzard and Pawn Storm, has been identified as the orchestrator of a new spear-phishing campaign targeting Ukraine and its allies. This campaign aims to deploy a novel malware suite named PRISMEX. According to Trend Micro researchers Feike Hacquebord and Hiroyuki Kakara, PRISMEX utilizes advanced techniques such as steganography, Component Object Model (COM) hijacking, and the misuse of legitimate cloud services for command-and-control operations. The campaign has been active since at least September 2025, focusing on various sectors in Ukraine and its allies.
The targets of this campaign include central executive bodies, hydrometeorology, defense, and emergency services in Ukraine, as well as rail logistics in Poland, maritime and transportation sectors in Romania, Slovenia, and Turkey, and logistical partners involved in ammunition initiatives in Slovakia and the Czech Republic. Military and NATO partners are also on the list of targets. The campaign is characterized by the rapid exploitation of newly disclosed vulnerabilities, such as CVE-2026-21509 and CVE-2026-21513, with infrastructure preparation noted as early as January 12, 2026.
In February 2025, Akamai reported that APT28 might have exploited CVE-2026-21513 as a zero-day vulnerability, using a Microsoft Shortcut (LNK) exploit uploaded to VirusTotal before Microsoft released a fix in February 2026. This suggests that the threat actor had prior knowledge of these vulnerabilities before their public disclosure. A shared domain, "wellnesscaremed[.]com," used in campaigns exploiting both vulnerabilities, indicates a possible connection between the two, forming a sophisticated two-stage attack chain.
The attack chain involves the first vulnerability (CVE-2026-21509) forcing the victim's system to retrieve a malicious .LNK file, which then exploits the second vulnerability (CVE-2026-21513) to bypass security features and execute payloads without user warnings. The attacks result in the deployment of either MiniDoor, an Outlook email stealer, or a collection of malware components known as PRISMEX, which uses steganography to hide payloads within image files.
PRISMEX includes several components: PrismexSheet, a malicious Excel dropper using VBA macros; PrismexDrop, a native dropper for environment preparation; PrismexLoader, a proxy DLL extracting .NET payloads from a PNG image; and PrismexStager, a COVENANT Grunt implant using Filen.io cloud storage for command-and-control. Some aspects of this campaign were previously documented by Zscaler ThreatLabz under the name Operation Neusploit.
APT28's use of the open-source COVENANT command-and-control framework was first noted by the Computer Emergency Response Team of Ukraine (CERT-UA) in June 2025. PrismexStager is seen as an expansion of MiniDoor and NotDoor, a Microsoft Outlook backdoor used by the group in late 2025. In an incident in October 2025, the COVENANT Grunt payload was found to facilitate information gathering and execute a destructive wiper command, indicating potential espionage and sabotage motives.
Trend Micro highlights that this operation demonstrates Pawn Storm's aggressive nature and strategic intent to compromise Ukraine's supply chain and operational planning capabilities, along with its NATO partners. The focus on targeting supply chains, weather services, and humanitarian corridors supporting Ukraine suggests a shift towards operational disruption, potentially leading to more destructive activities in the future.


