Operation MacroMaze: New APT28 Campaign Using Basic Tooling and Legitimate Infrastructure
Feb. 17, 2026, 4:08 p.m.
Description
Operation MacroMaze, attributed to APT28 (Fancy Bear), targets entities in Western and Central Europe from September 2025 to January 2026. The campaign utilizes basic tools and legitimate services for infrastructure and data exfiltration. Multiple documents with varying macro variants act as droppers, establishing a foothold by creating files in the %USERPROFILE% folder. The attack chain involves VBScript execution, scheduled task creation for persistence, and a multi-stage process using batch files. Exfiltration is achieved through HTML-based techniques, leveraging webhook.site for data transmission. Despite its simplicity, the campaign demonstrates effective operational tradeoffs, making detection and attribution challenging.
Tags
Date
- Created: Feb. 16, 2026, 2:28 p.m.
- Published: Feb. 16, 2026, 2:28 p.m.
- Modified: Feb. 17, 2026, 4:08 p.m.
Indicators
- df60fa6008b1a0b79c394b42d3ada6bab18b798f3c2ca1530a3e0cb4fbbbe9f6
- 9097d9cf5e6659e869bf2edf766741b687e3d8570036d853c0ca59ae72f9e9fc
- 58cfb8b9fee1caa94813c259901dc1baa96bae7d30d79b79a7d441d0ee4e577e
- 5486107244ecaa3a0824895fa432827cc12df69620ca94aaa4ad75f39ac79588
- c3b617e0c6b8f01cf628a2b3db40e8d06ef20a3c71365ccc1799787119246010
- ed8f20bbab18b39a67e4db9a03090e5af8dc8ec24fe1ddf3521b3f340a8318c1
- b0f9f0a34ccab1337fbcca24b4f894de8d6d3a6f5db2e0463e2320215e4262e4
Additional Informations
- Government
- Spain