216.73.216.6

Danger Bulletin: Cyberattacks Against Ukraine and EU Countries Using CVE-2026-21509 Exploit

· Published 04/02/2026 14:15 · Modified 09/02/2026 12:12

Export JSON

Essential information

Published
04/02/2026 14:15
Modified
09/02/2026 12:12
Tags
2026-02-04 CVE-2026-21509 com hijacking covenant eu filen microsoft office ukraine webdav
Related entities
1 vulnerabilities (cve), 34 observables, 1 intrusion sets (apt), 12 techniques (mitre), 1 malware, 5 others

Description

UAC-0001 (APT28) has launched cyberattacks against and countries exploiting the vulnerability in products. The threat actor created malicious DOC files targeting government bodies and organizations. The attack chain involves connections, , and the use of the framework, which utilizes cloud storage for command and control. The campaign began shortly after the vulnerability's disclosure, with multiple documents discovered containing similar exploits. The attackers employ sophisticated techniques to evade detection and maintain persistence, including disguising malicious files as legitimate Windows components and creating scheduled tasks.

External references