đ° Full Story
Microsoft disclosed a critical Office vulnerability, tracked as CVE-2026-21509, on Jan. 26, 2026.
Ukrainian cyber-defence agency CERT-UA reported that Russia-linked UAC-0001 (APT28/Fancy Bear) weaponized the bug within days: a malicious document created Jan. 27 and themed around EU consultations surfaced publicly, and a Jan. 29 phishing campaign impersonating the Ukrhydrometeorological Center targeted more than 60 central government addresses.
The attack chain uses a DOC that opens a WebDAV connection to download a shortcut, which launches a DLL (reported as EhStoreShell.dll) and hides shellcode in an image (SplashScreen.png). Persistence is achieved via COM hijacking and a scheduled task named âOneDriveHealth.â The final payload is the COVENANT post-exploitation framework, with command-and-control traffic routed through legitimate Filen cloud storage to evade detection.
CERT-UA and industry reports found similar documents targeting EU organizations in late January and observed rapid domain registration on the day of use.
Microsoft has released patches, including for older builds, but CERT-UA warned exploitation will likely increase given slow patch rollouts and incomplete mitigations.
Defenders are advised to apply Microsoftâs mitigations, monitor Filen-related traffic, and treat unsolicited geopolitical-themed Office attachments as high risk.







đŹ Commentary