CVE-2023-23397
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: microsoft Outlook Elevation of Privilege Vulnerability EPSS 97% (100th percentile).
CISA federal remediation date Apr 4 · date passed
Threats & Adversaries · APT / Espionage
APT28 is becoming harder to catch by design. The group is moving away from one stable implant and toward short-lived modules, edge-hosted infrastructure, and malware that can interact with an LLM, which shortens the window where any one fingerprint stays useful.
Sekoia’s report says this is an evolution in tradecraft, not just a new target set. It ties the shift to APT28’s long-running activity against government, defense, diplomatic, and critical infrastructure targets, and frames the change as a move from reusable indicators to rapidly replaced collection pieces.
For hunters, the break is in the operating model: one module or one node no longer tells you much about the rest of the campaign. The same actor can now look like a sequence of small, low-signal events that expire before traditional indicator-based tracking catches up.
1 source · Jun 11
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: microsoft Outlook Elevation of Privilege Vulnerability EPSS 97% (100th percentile).
CISA federal remediation date Apr 4 · date passed
Known exploited · CISA KEV
CVSS 7.8 HIGH: windows Print Spooler Elevation of Privilege Vulnerability EPSS 15% (96th percentile).
CISA federal remediation date May 14 · date passed
Sekoia.io
APT28, an evolution of tradecraft
Context Sekoia’s Threat Detection & Research (TDR) team has been tracking APT28 for several years.
originalPart of the PlainSec briefing for 2026-06-11
Every edition of this story: APT28’s tooling is now disposable