<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Russian Hackers Exploit Microsoft Office Zero-Day in Eastern Europe Attacks

APT28 exploits Microsoft Office zero-day to target Ukraine, Slovakia, and Romania with malware via weaponized RTF documents.
Content Team

Russia's APT28 hacking group is actively exploiting a critical Microsoft Office zero-day vulnerability to target victims across Ukraine, Slovakia, and Romania. The attackers send weaponized RTF documents in local languages that silently install malware when opened.

Zscaler researchers discovered the campaign in January 2026, with active attacks occurring just three days after Microsoft's emergency patch on January 26. The hackers deploy two types of malware: MiniDoor steals emails from Outlook, while PixyNetLoader provides remote access to compromised systems.

The sophisticated operation uses geographic filtering to evade detection, only delivering payloads to targets in specific regions with correct HTTP headers.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo