logo

5463

ID: c7e61682-7287-43cf-8d44-c5c37e2d1fc5

STIX ID: report--c7e61682-7287-43cf-8d44-c5c37e2d1fc5

Threat Score

90/100

Uploaded: 2026-05-19

Created by: team123

TLP:GREEN
...
...
Trend Micro attributed a Russia-linked APT28 campaign deploying a PRISMEX malware suite against Ukrainian government, military and allied critical infrastructure (Poland, Romania, Slovakia) beginning September 2025; attackers exploited zero-day vulnerabilities CVE-2026-21509 and CVE-2026-21513 via spearphishing to force systems to WebDAV servers and execute malicious LNK files, using PrismexSheet/Drop/Loader/Stager, steganography, COM hijacking and Filen.io for C2, with decoy military logistics documents and a reported shift toward disruptive targeting of supply chains and NATO-linked logistics.