CVE-2023-23397
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: microsoft Outlook Elevation of Privilege Vulnerability EPSS 97% (100th percentile).
CISA federal remediation date Apr 4 · date passed
Threats · 96 days ago
APT28 is becoming harder to catch by design. The group is moving away from one stable implant and toward short-lived modules, edge-hosted infrastructure, and malware that can interact with an LLM, which shortens the window where any one fingerprint stays useful.
Sekoia’s report says this is an evolution in tradecraft, not just a new target set. It ties the shift to APT28’s long-running activity against government, defense, diplomatic, and critical infrastructure targets, and frames the change as a move from reusable indicators to rapidly replaced collection pieces.
For hunters, the break is in the operating model: one module or one node no longer tells you much about the rest of the campaign. The same actor can now look like a sequence of small, low-signal events that expire before traditional indicator-based tracking catches up.
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: microsoft Outlook Elevation of Privilege Vulnerability EPSS 97% (100th percentile).
CISA federal remediation date Apr 4 · date passed
Known exploited · CISA KEV
CVSS 7.8 HIGH: windows Print Spooler Elevation of Privilege Vulnerability EPSS 15% (96th percentile).
CISA federal remediation date May 14 · date passed
1 source covering this story
APT28, an evolution of tradecraft
Context Sekoia’s Threat Detection & Research (TDR) team has been tracking APT28 for several years.
Part of the PlainSec briefing for 2026-06-12