APT28 Expands Supply-Chain Attacks Using Fresh Office Zero-Days

APT28 has moved beyond spear-phishing to operationalize new Office and MSHTML zero-day vulnerabilities, rapidly deploying their PRISMEX malware suite. This shift means defenders face a broader blast radius that includes supply-chain and transport organizations, not just the initial phishing targets. The malware’s use of legitimate cloud services, COM hijacking, and steganography complicates detection and cleanup, making simple patching or IOC blocking insufficient. Trend Micro and Akamai confirm PRISMEX has been active since September 2025, exploiting CVE-2026-21509 and CVE-2026-21513 before public disclosure. The campaign targets Ukraine, NATO partners, and critical logistics sectors across multiple countries, with infrastructure prepared weeks ahead of vulnerability announcements. The use of a common domain and coordinated timing suggests a sophisticated two-stage attack chain designed for espionage and supply-chain disruption. This rapid weaponization compresses defenders’ patch window and raises immediate risks to military and humanitarian logistics networks. The campaign’s focus on transport and supply nodes means a single successful phishing attack can cascade into broader operational impacts, underscoring the need to anticipate zero-day exploitation as an immediate threat rather than a future possibility.

Part of the PlainSec briefing for 2026-04-09

Sources