APT28 Uses Microsoft Office CVE-2026-21509 in Espionage-Focused Malware Attacks
Attacks using a recently revealed Microsoft Office security vulnerability have been linked to the Russia-affiliated state-sponsored threat actor APT28 (also known as UAC-0001) as part of a campaign called Operation Neusploit.
Three days after Microsoft made the bug public, on January 29, 2026, Zscaler ThreatLabz reported that it saw the hacker organization using the vulnerability as a weapon in assaults against people in Romania, Slovakia, and Ukraine.
CVE-2026-21509 (CVSS score: 7.8) is a Microsoft Office security feature bypass vulnerability that could enable an unauthorized attacker to deliver a specially designed Office file and cause it to activate.
According to security experts Sudeep Singh and Roy Tay, social engineering lures were created in both English and localized lan...



