APT28, a state-sponsored threat actor associated with Russia, has been linked to a recent campaign that targets particular organizations in Western and Central Europe.
The LAB52 threat intelligence team of S2 Grupo reports that the action took place between September 2025 and January 2026. “The campaign relies on basic tooling and the exploitation of legitimate services for infrastructure and data exfiltration,” the cybersecurity firm stated, referring to it by the codename Operation MacroMaze.
To disseminate lure documents with a common structural element in their XML, a field called “INCLUDEPICTURE” that leads to a webhook[.]site URL that stores a JPG picture, the attack chains use spear-phishing emails as a starting point. Consequently, when the document is opened, the image file is retrieved from the distant server.
In other words, when the page is opened, this technique functions as a beaconing method similar read more about APT28 Targeted European Entities Using Webhook-Based Macro Malware.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
