APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies

APT28 (also known as Forest Blizzard and Pawn Storm), a Russian threat actor, has been connected to a new spear-phishing campaign that targets Ukraine and its allies in order to install a malware suite called PRISMEX that has never been documented.

According to a technical paper by Trend Micro experts Feike Hacquebord and Hiroyuki Kakara, PRISMEX combines advanced steganography, component object model (COM) hijacking, and lawful cloud service exploitation for command-and-control. It is thought that the campaign has been going on since at least September 2025.

Central executive bodies, hydrometeorology, defense, emergency services, rail logistics (Poland), maritime and transportation (Romania, Slovenia, Turkey), logistical support partners involved in ammunition initiatives (Slovakia, Czech Republic), and military and NATO partners are just a few of the sectors in Ukraine that have been targeted by the activity.

The effort is noteworthy for the quick weaponization of recently discovered vulnerabilities read more about APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *