Pawn Storm (APT28) Deploys PRISMEX Malware Suite via CVE-2026-21509 and CVE-2026-21513 Zero-Days Targeting Ukrainian Defense Supply Chain — Threadlinqs Intelligence
As of 2026-05-30, Pawn Storm (APT28) Deploys PRISMEX Malware Suite via CVE-2026-21509 and CVE-2026-21513 Zero-Days Targeting Ukrainian Defense Supply Chain is a critical-severity apt threat attributed to APT28 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-0285 · Severity: CRITICAL · CVSS: 8.8 · Status: ACTIVE · Category: APT
Attribution: APT28 · Russia · ESPIONAGE
Russia-aligned APT28 (Pawn Storm/Fancy Bear/UAC-0001) has deployed PRISMEX, a sophisticated multi-stage malware suite combining steganography, COM hijacking, and Filen.io cloud abuse for C2, targeting
In a sustained espionage campaign active since at least September 2025, Russia's GRU-linked APT28 (also tracked as Pawn Storm, Fancy Bear, UAC-0001, and Forest Blizzard) has deployed a comprehensive malware toolkit collectively designated PRISMEX by Trend Micro, targeting Ukrainian defense supply chain entities, NATO logistics hubs, and government agencies across Central and Eastern Europe.
The campaign leverages two Microsoft vulnerabilities as initial access vectors. CVE-2026-21509 (CVSS 7.8) is a Microsoft Office OLE security feature bypass disclosed on January 26, 2026, which APT28 weaponized within 24 hours using spear-phishing RTF documents with geopolitically themed lures in English, Romanian, Slovak, and Ukrainian. The exploit bypasses OLE security restrictions, exposing unsafe COM controls to execution and triggering WebDAV requests to retrieve next-stage payloads from attacker-controlled servers. CVE-2026-21513 (CVSS 8.8) is an MSHTML Framework zero-day rooted in insufficient URL validation within ieframe.dll's hyperlink navigation logic, allowing attacker-controlled input to reach ShellExecuteExW for code execution outside the browser sandbox. A malicious sample was uploaded to VirusTotal on January 30, 2026 — 11 days before Microsoft's February 10 patch — confirming zero-day exploitation. The exploit uses specially crafted LNK files embedding HTML content with nested iframes to bypass Mark-of-the-Web (MotW) and Internet Explorer Enhanced Security Configuration.
The PRISMEX infection chain follows two primary execution variants. Variant 1 deploys MiniDoor, a lightweight 64-bit C++ DLL that implements Outlook email theft. MiniDoor injects a malicious VBA project into Outlook, monitoring MAPILogonComplete and Application_NewMailEx events to silently forward emails from Inbox, Junk, Drafts, and RSS folders to threat actor-controlled addresses (ahmeclaw2002@outlook.com and ahmeclaw@proton.me). It uses a hardcoded single-byte XOR key (0x3a) for initial decryption and a 58-byte rolling XOR key for VBA project decryption. MiniDoor modifies Outlook security registry settings to enable macro execution and weakens security controls. Variant 2 deploys PixyNetLoader, a previously undocumented dropper that writes EhStoreShell.dll (shellcode loader), SplashScreen.png (steganographic payload), and office.xml (scheduled task config) to disk. Persistence is achieved through COM object hijacking targeting CLSID {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}, spoofing the Enhanced Storage Shell Extension. A scheduled task named 'OneDriveHealth' triggers explorer.exe restart and loads the hijacked COM object. EhStoreShell.dll implements sandbox evasion by verifying Sleep() API timing (must exceed 2.9 seconds), then extracts shellcode from SplashScreen.png using LSB steganography — each pixel's RGBA channels store data in least significant bits, requiring 2 pixels per encoded byte. The extracted shellcode uses CLR hosting to load a Covenant Grunt .NET implant that communicates via the Filen.io cloud storage API as a C2Bridge, with XOR encoding using key 'EIZ4EG2K8R' and Base64 encoding.
Additional tooling includes BEARDSHELL, a PowerShell command execution backdoor using Icedrive cloud storage for C2 with 'opaque predicate' obfuscation, and SLIMAGENT, a keylogger and screenshotter with HTML output formatting evolved from the XAgent platform. SimpleLoader serves as a LNK/DLL component for downloading additional payloads using three distinct XOR encryption schemes.
The campaign has employed server-side geofencing, responding with malicious DLLs only when requests originate from targeted geographic regions with correct User-Agent headers. Analysis of compromised Filen.io infrastructure revealed victim accounts distributed across multiple compromised or attacker-created accounts. The campaign's C2 infrastructure has evolved through pCloud (2023), Koofr (2024-2025), and now Filen.io (July 2025-present), demonstrating operational flexibility in s
Weaknesses (CWE)
CWE-807, CWE-693
Target sectors: government, defense, critical-infrastructure, maritime-transport, rail-logistics, hydrometeorology, emergency-services, humanitarian-aid, military
Target regions: Ukraine, Poland, Romania, Slovenia, Turkey, Slovakia, Czech Republic, Greece, United Arab Emirates, Central Europe, Eastern Europe
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, CRITICAL, threat intelligence, cybersecurity, CVE-2026-21509, CVE-2026-21513, T1566, T1203, T1204, T1204, T1059, T1059, T1106, T1546, T1053, T1137