APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies
Introduction
Sophisticated state-sponsored groups pose a persistent threat in cybersecurity. APT28, a Russian state-linked actor, has deployed a previously undocumented malware suite, PRISMEX, in a campaign targeting Ukraine and its allies. This operation demonstrates advanced tactics, including zero-day exploitation and novel steganographic techniques.
Security organizations are also addressing other critical vulnerabilities. CISA recently issued a directive for federal agencies to patch a zero-day flaw in Ivanti Endpoint Manager Mobile (EPMM), identified as CVE-2026-1340, which has been exploited in the wild since January. Separately, a zero-day vulnerability in Adobe Reader has been under active exploitation since December 2025, using specially crafted PDF documents.
These events demonstrate the continuous need for advanced cyber threat intelligence platform capabilities. These platforms help understand adversary methods, anticipate attack vectors, and implement effective defenses. The increasing speed of zero-day weaponization and the growing influence of AI in both offensive and defensive cybersecurity operations demand a data-driven approach to security.
APT28 Deploys PRISMEX Malware in Strategic Operations
The Russian threat actor APT28, also known as Forest Blizzard and Pawn Storm, has initiated a spear-phishing campaign that targets Ukrainian entities and various NATO allies. This campaign uses a new, stealthy malware suite named PRISMEX. Analysis by Trend Micro researchers Feike Hacquebord and Hiroyuki Kakara indicates that the campaign has been active since at least September 2025.
The PRISMEX malware combines several advanced techniques to achieve its objectives. These include sophisticated steganography, Component Object Model (COM) hijacking, and the abuse of legitimate cloud services for command-and-control (C2) communication. Such methods aim to evade traditional breach detection mechanisms and maintain persistence within compromised environments.
What are the primary targets of the APT28 PRISMEX campaign?
The APT28 campaign targets a range of critical sectors and organizations across Ukraine and its partners. In Ukraine, targets include central executive bodies, hydrometeorology, defense, and emergency services. Beyond Ukraine, the campaign extends to rail logistics in Poland; maritime and transportation sectors in Romania, Slovenia, and Turkey; and logistical support partners involved in ammunition initiatives in Slovakia and the Czech Republic. Military and NATO partners also feature as targets. This targeting pattern suggests a strategic intent to compromise operational planning capabilities and disrupt supply chains, a significant concern for supply-chain risk monitoring.
How does APT28 weaponize zero-day vulnerabilities?
APT28 demonstrates rapid weaponization of newly disclosed vulnerabilities. The group quickly exploited CVE-2026-21509 and CVE-2026-21513 to breach target systems. Infrastructure preparation for these exploits was observed on January 12, 2026, two weeks before CVE-2026-21509 became publicly known.
Further analysis by Akamai in late February 2025-indicated that CVE-2026-21513 may have been weaponized as a zero-day. A Microsoft Shortcut (LNK) exploit related to this vulnerability was uploaded to VirusTotal on January 30, 2026, preceding Microsoft's patch release on February 10, 2026. This timeline suggests the threat actor had prior knowledge of these vulnerabilities.
The domain "wellnesscaremed[.]com" was common to campaigns exploiting both CVE-2026-21513 and CVE-2026-21509. This commonality, combined with the exploitation timing, suggests the possibility of a sophisticated two-stage attack chain. In this theoretical chain, CVE-2026-21509 would force the victim's system to retrieve a malicious .LNK file, which then exploits CVE-2026-21513 to bypass security features and execute payloads without user interaction.
What PRISMEX malware components are deployed by APT28?
The attacks culminate in the deployment of either MiniDoor, an Outlook email stealer, or the interconnected components of the PRISMEX malware suite. PRISMEX is named for its use of steganography to hide payloads within image files. The suite includes:
- PrismexSheet: This is a malicious Excel dropper that uses VBA macros. It extracts hidden payloads embedded within the Excel file via steganography and achieves persistence through COM hijacking. After macros are enabled, it displays a decoy document, often related to drone inventory lists and prices.
- PrismexDrop: A native dropper responsible for preparing the environment for subsequent exploitation. It ensures persistence using scheduled tasks and COM DLL hijacking.
- PrismexLoader (also known as PixyNetLoader): A proxy DLL that extracts the next-stage .NET payload. This payload is scattered across the file structure of a PNG image named "SplashScreen.png" and is reconstructed using a custom "Bit Plane Round Robin" algorithm. It executes entirely in memory, reducing its footprint on disk.
- PrismexStager: Identified as a COVENANT Grunt implant, this component uses Filen.io cloud storage for its C2 communications. The use of COVENANT, an open-source command-and-control framework, was previously noted by the Computer Emergency Response Team of Ukraine (CERT-UA) in June 2025.
Aspects of this campaign were previously detailed by Zscaler ThreatLabz under the designation Operation Neusploit. PrismexStager is considered an extension of earlier APT28 backdoors like MiniDoor and NotDoor (aka GONEPOSTAL), which also targeted Microsoft Outlook and were deployed in late 2025.
A specific incident in October 2025 involved the COVENANT Grunt payload facilitating information gathering. This payload also executed a destructive wiper command, erasing all files under the "%USERPROFILE%" directory. This dual capability suggests an intent for both espionage and sabotage operations, which aligns with the group's reputation for targeting critical infrastructure and government entities. Such activities are closely monitored by cyber threat intelligence platform providers and require complete real-time ransomware intelligence for rapid response, even when the intent is sabotage rather than financial gain.
Trend Micro's assessment notes that Pawn Storm remains an aggressive Russia-aligned intrusion set. The strategic focus on compromising supply chains, weather services, and humanitarian corridors supporting Ukraine indicates a shift toward operational disruption. This emphasizes the need for strong supply-chain risk monitoring and advanced breach detection capabilities.
CISA Directs Federal Agencies to Patch Exploited Ivanti EPMM Flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that U.S. government agencies patch a critical-severity vulnerability in Ivanti Endpoint Manager Mobile (EPMM) by Saturday, April 11. This flaw, tracked as CVE-2026-1340, is a code injection vulnerability. Threat actors, even those without prior privileges, have exploited this flaw to achieve remote code execution (RCE) on internet-exposed and unpatched EPMM appliances.
Ivanti had previously warned about CVE-2026-1340 and a second security flaw, CVE-2026-1281, on January 29, confirming both were being exploited as zero-days. The company urged all customers to update their systems immediately to prevent further exploitation. This proactive measure is part of broader efforts to manage supply-chain risk monitoring in enterprise software.
Internet security tracking group Shadowserver reports approximately 950 IP addresses with Ivanti EPMM fingerprints remain exposed online. The majority of these are located in Europe (569) and North America (206). The number of these systems that have applied the necessary patches is currently unknown.
CISA added CVE-2026-1340 to its Known Exploited Vulnerabilities (KEV) Catalog. The agency's directive, mandated by Binding Operational Directive (BOD) 22-01, targets Federal Civilian Executive Branch (FCEB) agencies. CISA described this type of vulnerability as a frequent attack vector that poses significant risks to federal enterprises. The recommendation extends to all defenders, including those in the private sector. It emphasizes the priority of patching CVE-2026-1340 to secure organizational devices promptly. Past incidents show that CISA has tagged 33 Ivanti vulnerabilities as exploited, with 12 used by various ransomware operations. This highlights the critical nature of these patches and the need for real-time ransomware intelligence.
Adobe Reader Zero-Day Exploitation Since December
Attackers have been exploiting a zero-day vulnerability in Adobe Reader since at least December 2025. These attacks are carried out using maliciously crafted PDF documents. The vulnerability was identified by security researcher Haifei Li, founder of the sandbox-based exploit-detection platform EXPMON.
Li characterized the exploit as a "sophisticated, fingerprinting-style PDF exploit." This attack operates on the latest version of Adobe Reader and does not require user interaction beyond opening the malicious PDF file. The compromise allows threat actors to collect and steal local information. This data exfiltration is achieved through privileged util.readFileIntoStream and RSS.addFeed Acrobat APIs. The exploit also provides a pathway for subsequent RCE/SBX (Remote Code Execution/Sandbox Escape) attacks, potentially leading to full control of a victim's system. Such activities are often preceded by reconnaissance, which may involve dark web monitoring service or underground forum intelligence.
Threat intelligence analyst Gi7w0rm observed that the PDF documents distributed in these attacks often contain Russian-language lures. These lures reference current events within the Russian oil and gas industry, suggesting specific targeting. Effective dark web monitoring service and telegram threat monitoring could detect pre-attack discussions or distribution of such malicious documents.
Haifei Li has reported these findings to Adobe. Until security updates are released, users of Adobe Reader are advised not to open PDF documents from untrusted contacts. Network defenders can implement a temporary mitigation by monitoring and blocking HTTP/HTTPS traffic that contains the "Adobe Synchronizer" string in the User-Agent header. This demonstrates the constant need for proactive breach detection and threat intelligence to counter zero-day exploits.
AI's Impact on Zero-Day Discovery and Threats
The emergence of advanced AI models has begun to redefine the dynamics of cybersecurity, particularly concerning zero-day vulnerabilities. Anthropic's new AI model is reportedly capable of discovering thousands of zero-days at an accelerated rate. This development represents a significant inflection point, influencing both offensive and defensive cybersecurity strategies.
The capacity for AI to rapidly uncover and chain vulnerabilities at scale introduces a new challenge for organizations. It prompts questions regarding the speed of remediation for discovered flaws, the security of legacy systems, and the future evolution of security tools. Phil Venables, Google's CISO, has previously noted that AI will accelerate vulnerability discovery and enhance attacker capabilities. This suggests threats may intensify before improved defensive measures become widely effective. This reinforces the need for advanced cyber threat intelligence platform capabilities to track and predict these changes.
AI's role in democratizing cybercrime is a growing concern. By automating complex attack processes, AI makes sophisticated attacks more accessible to a wider range of malicious actors. This includes activities such as developing tailored spear-phishing campaigns, generating convincing social engineering content, and identifying vulnerable targets through automated reconnaissance. Such widespread access to advanced attack tools makes dark web monitoring service and underground forum intelligence increasingly critical for threat anticipation.
The fundamental challenge is how organizations manage and contain vulnerabilities at scale, beyond just discovering them faster with AI. Effective management requires improved visibility into IT environments, faster remediation cycles, and adaptive defenses capable of responding to AI-driven threats. An example of this challenge is observed in Russian espionage campaigns that use outdated routers. This shows how even seemingly minor vulnerabilities can be exploited for significant strategic gains. This shows the importance of full supply-chain risk monitoring and continuous asset vulnerability assessment.
Technical Takeaways
- APT28's PRISMEX malware uses steganography, COM hijacking, and cloud service abuse for C2, demonstrating complex evasion techniques.
- The group rapidly weaponized CVE-2026-21509 and CVE-2026-21513, with infrastructure preparation preceding public disclosure, indicating zero-day exploitation capabilities.
- PRISMEX components like PrismexLoader use custom algorithms to extract payloads from seemingly benign image files, running them in memory for stealth.
- CISA issued a directive for CVE-2026-1340 in Ivanti EPMM, a critical code injection flaw actively exploited for RCE on unpatched internet-facing systems.
- A zero-day in Adobe Reader is exploited via malicious PDFs, allowing data exfiltration through privileged APIs and potential follow-on RCE/SBX attacks, with Russian-language lures observed.
- AI's ability to rapidly discover and chain zero-day vulnerabilities is changing threat dynamics, making proactive cyber threat intelligence platform solutions and breach detection more critical.
FAQ
Q: What is APT28, and what is its primary objective with PRISMEX?
APT28, also known as Forest Blizzard or Pawn Storm, is a Russian state-linked threat actor. Its primary objective with the PRISMEX malware campaign is espionage and potential sabotage against Ukraine and its NATO allies, specifically targeting supply chains and operational planning.
Q: Which zero-day vulnerabilities were exploited in the recent APT28 campaign?
The recent APT28 campaign involved the rapid exploitation of CVE-2026-21509 and CVE-2026-21513. These vulnerabilities were weaponized quickly, with evidence suggesting the threat actor had knowledge of the flaws before their public disclosure.
Q: What is CVE-2026-1340, and why is CISA urging immediate patching for Ivanti EPMM?
CVE-2026-1340 is a critical-severity code injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that permits unauthenticated remote code execution. CISA mandated immediate patching because it has been actively exploited in the wild since January, posing a significant risk to federal agencies and other organizations.
Q: How are threat actors using AI to enhance cyberattacks?
Threat actors are using AI to accelerate vulnerability discovery, improve the efficacy of social engineering, and automate the execution of sophisticated attacks. This reduces the barrier to entry for complex cybercrime and demands more advanced cyber threat intelligence platform capabilities.
Q: What immediate mitigation steps can be taken for the Adobe Reader zero-day?
Until a patch is released, users should avoid opening PDF documents from untrusted sources. Network defenders can also monitor and block HTTP/HTTPS traffic containing the "Adobe Synchronizer" string in the User-Agent header as a temporary breach detection and prevention measure.