APT28 Operation Neusploit: MS Office CVE-2026-21509 Espionage Campaign — Threadlinqs Intelligence
As of 2026-05-30, APT28 Operation Neusploit: MS Office CVE-2026-21509 Espionage Campaign is a critical-severity apt threat attributed to APT28 (Russia), tracked by Threadlinqs Intelligence with 14 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 47 indicators of compromise.
Threat ID: TL-2026-0052 · Severity: CRITICAL · CVSS: 7.8 · Status: PATCHED · Category: APT
Attribution: APT28 · Russia · ESPIONAGE
APT28 (Fancy Bear / Forest Blizzard / GRU Unit 26165) is conducting Operation Neusploit, a targeted espionage campaign weaponizing CVE-2026-21509 — the Microsoft Office OLE compound document security
Operation Neusploit — APT28/GRU CVE-2026-21509 Weaponized Espionage Campaign:
Threat Actor Profile — APT28:
APT28 (also tracked as Fancy Bear, Forest Blizzard, STRONTIUM, Pawn Storm, Sednit, Sofacy, Iron Twilight, Tsar Team, GruesomeLarch, FROZENLAKE, and Group 74) is a Russian state-sponsored cyber espionage unit attributed to the Russian Main Intelligence Directorate (GRU), specifically Unit 26165 of the 85th Main Special Service Center (GTsSS). Active since at least 2004, APT28 is one of the most prolific and technically sophisticated nation-state threat actors globally.
APT28 has conducted campaigns against: the Democratic National Committee (DNC, 2016), the World Anti-Doping Agency (WADA), the Organisation for the Prohibition of Chemical Weapons (OPCW), the German Bundestag, the French TV5Monde, Norwegian and Swedish military targets, Ukrainian government and military, NATO institutions, and countless government/defense organizations worldwide. In 2018, the DOJ indicted 12 GRU officers for the DNC hack.
Operation Neusploit — Kill Chain:
1. Reconnaissance (TA0043):
- APT28 conducts extensive pre-compromise reconnaissance on target organizations
- Harvests email addresses, organizational charts, and communication patterns of key personnel
- Identifies MS Office versions in use via email header analysis and document metadata
- Maps network architecture through OSINT of job postings, technical forums, and vendor relationships
- Targets selected for strategic intelligence value: defense attachés, NATO planners, foreign ministry officials, energy sector executives
2. Weaponization (TA0042):
- CVE-2026-21509 exploit integrated into OLE compound document structure
- Malicious .docx files crafted with embedded OLE objects that bypass Protected View
- Three delivery variants observed:
a) Direct OLE exploit — malicious OLE object auto-executes on document open (bypasses Protected View)
b) OLE-to-macro chain — OLE bypass disables Protected View, enabling embedded macro execution
c) OLE-to-DDE chain — OLE bypass enables Dynamic Data Exchange (DDE) command execution
- NEUSPLOIT implant: new modular backdoor written in C++ with encrypted C2 communication
- Payload stages: Stage 0 (OLE exploit) → Stage 1 (HEADLACE loader DLL) → Stage 2 (NEUSPLOIT backdoor)
3. Delivery (TA0001):
- Spearphishing emails crafted with high-quality social engineering
- Lure themes: NATO exercise planning documents, defense procurement briefings, diplomatic cables, energy security assessments, Ukraine situation reports
- Sender spoofing: compromised legitimate email accounts from allied organizations and think tanks
- Delivery infrastructure: VPS providers (DigitalOcean, Hetzner), compromised Ubiquiti EdgeRouters, typosquatted domains mimicking NATO/government sites
- Attached .docx files with convincing filenames: 'NATO_STEADFAST_DEFENDER_2026_BRIEF.docx', 'UA_SITREP_FEB2026_CLASSIFIED.docx', 'ENERGY_SECURITY_ASSESSMENT_Q1.docx'
4. Exploitation (TA0002):
- User opens malicious .docx → CVE-2026-21509 OLE exploit triggers
- Protected View bypassed — document opens in full editing mode without sandbox
- OLE object executes embedded payload: PowerShell or cmd.exe command
- Stage 1: HEADLACE loader DLL side-loaded via legitimate Microsoft signed binary (DLL search order hijacking)
- HEADLACE establishes initial C2 beacon, downloads NEUSPLOIT from staging server
- Execution chain: winword.exe → OLE exploit → cmd.exe/powershell.exe → rundll32.exe (HEADLACE) → NEUSPLOIT
5. Persistence (TA0003):
- Registry Run Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run → legitimate-sounding entry
- Logon Script: HKCU\Environment\UserInitMprLogonScript (documented APT28 technique)
- Scheduled Task: schtasks.exe with legitimate task name ('Microsoft Office Telemetry')
- Startup Folder: NEUSPLOIT shortcut in %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
- COM Object Hijacking: replacing legitimate COM DLL with NEUSPLOIT loader
6. Command and Control
Target sectors: Government, Defense, Diplomatic, Military, Critical Infrastructure, Energy, Think Tanks, International Organizations
Target regions: NATO Countries, Ukraine, United States, European Union, United Kingdom, Germany, France, Poland, Baltics
Detections & IOCs
As of 2026-07-28, this threat has 14 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 47 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, CRITICAL, threat intelligence, cybersecurity, CVE-2026-21509, T1566.001, T1204.002, T1027, T1589, T1591, T1595, T1583, T1583, T1584, T1586