Advertisement

APT28 Targets Ukraine and NATO Allies with New PRISMEX Malware
APT28 (Forest Blizzard) deploys the undocumented PRISMEX malware suite against Ukraine and NATO, utilizing COM hijacking and cloud-based C2 infrastructure.

APT28 Exploits MikroTik & TP-Link Routers in DNS Hijacking
Russian state-linked APT28 (Forest Blizzard) is compromising insecure SOHO routers globally, employing DNS hijacking for cyber espionage since May 2025.
APT28 FrostArmada DNS Hijack Campaign Steals Microsoft 365 Logins
Authorities disrupt APT28's FrostArmada campaign, which used DNS hijacking of MikroTik and TP-Link routers to steal Microsoft 365 account credentials.
Star Blizzard (APT28) Adopts DarkSword iOS Exploit Kit
Russian APT Star Blizzard (APT28) now uses the DarkSword iOS exploit kit to target government, finance, and academia, increasing mobile threat exposure.
APT28 Targets Ukraine via CVE-2024-45519 Zimbra Exploit
Russian APT28 hackers exploit CVE-2024-45519 in Zimbra Collaboration Suite to target Ukrainian government entities via malicious email-based command injection.
Sednit/APT28 Resurfaces: Advanced Toolkit Threat Analysis
Russian-affiliated APT Sednit (APT28) has returned with sophisticated new malware, shifting from simple implants. Understand their updated TTPs and mitigation strategies.
AI-Enhanced Cyberattacks: Microsoft Details LLM Abuse by APT Groups
Microsoft reveals how nation-state actors like APT28 and Crimson Sandstorm are using AI to automate reconnaissance and refine social engineering lures.
Russian Coruna iOS Exploit Kit Targets Global Users — Analysis
Security researchers uncover the Coruna iOS exploit kit, a nation-state tool now used in broader campaigns to deliver spyware to mobile devices.

APT28 Exploits CVE-2026-21513: MSHTML 0-Day Intelligence
Akamai reports Russia-linked APT28 exploited CVE-2026-21513 in the MSHTML Framework as a zero-day before Microsoft's February 2026 security patch updates.

January 2026 CVE Landscape: APT28 Zero-Day & Critical Flaws
Runtime Rebel details January 2026's 23 critical CVEs, including an APT28 zero-day in Microsoft Office and critical enterprise authentication bypass vulnerabilities.

APT28 Operation MacroMaze: Webhook-Driven Macro Execution Targeting Western Europe
Analysis of a targeted campaign attributed to APT28, utilizing macro-enabled documents and legitimate webhook services for command-and-control obfuscation.