Cyber Security News

Fancy Bear Hackers Exploiting Microsoft Zero-Day Vulnerability to Deploy Backdoors and Email Stealers

The Russia-linked cyber espionage group known as Fancy Bear has launched Operation Neusploit. The group is also known as APT28.

This marks a significant escalation, leveraging a zero-day vulnerability, CVE-2026-21509, in Microsoft RTF files.

By exploiting this flaw, attackers execute arbitrary code on victim systems, deploying dangerous backdoors and email stealers.

The campaign targets organizations in Central and Eastern Europe, posing a severe threat to government and military sectors in the region.

The attack distributes malicious RTF documents via phishing emails using social engineering lures written in English, Romanian, Slovak, and Ukrainian.

The primary targets are in Ukraine, Slovakia, and Romania. Attackers designed these documents to be highly convincing, often mimicking official government documents, increasing the likelihood victims trigger the exploit.

Polyswarm analysts identified the malware, noting its capability to bypass traditional security measures.

It employs evasion techniques, checking for specific User-Agent strings and verifying geographic locations before delivering the payload.

If conditions are met, the chain downloads a malicious dropper DLL, installing further malicious components.

Once compromised, the impact is severe. The malware steals sensitive information directly from Microsoft Outlook.

It monitors email activity, saves messages, and exfiltrates them to attacker-controlled servers.

Additionally, the malware establishes a persistent connection to a command-and-control server, allowing attackers to maintain long-term access and execute further commands. This communication is often encrypted to avoid detection.

Infection Mechanism and Persistence

The infection involves two dropper DLL variants. The first variant deploys MiniDoor, a tool that modifies registry keys to downgrade Outlook security and extract an encrypted script to steal emails.

The second variant introduces PixyNetLoader, which drops payloads like a PNG file hiding malicious shellcode using steganography.

To ensure persistence, attackers use COM hijacking. They register their malicious file under a legitimate name, forcing the OS to load it when Explorer restarts.

This sophisticated mechanism allows the malware to survive reboots and continue its espionage activities undetected. This technique makes detection extremely difficult for defenders.

AttributeDetails
CVE IdentifierCVE-2026-21509
Vulnerability TypeRTF Parsing Flaw / Arbitrary Code Execution
Affected ComponentMicrosoft RTF (Rich Text Format) File Parser
Associated CampaignOperation Neusploit
Threat ActorFancy Bear (APT28, Sofacy, Sednit)
Patch Release DateJanuary 26, 2026 (Out-of-band update)
Active ExploitationFirst detected in the wild on January 29, 2026
Attack VectorPhishing emails containing specially crafted malicious RTF attachments
Target GeographiesCentral and Eastern Europe (specifically Ukraine, Slovakia, and Romania)
ImpactDeployment of backdoors (MiniDoor, PixyNetLoader) and email stealers

Organizations should immediately apply the patch for CVE-2026-21509. Security teams must monitor network traffic for the specific User-Agent strings and indicators of compromise associated with Operation Neusploit.

It is also crucial to update email security gateways to filter out malicious RTF attachments. Security professionals should also consider blocking RTF files entirely if they are not needed for business operations.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago