Drooid Logo
Back to story perspectives

Full Breakdown

Fancy Bear Exploits Microsoft Office Vulnerability in Cyber Attacks

2/3/2026, 11:14:58 AM

Overview of the Cyber Attack

Russian-linked hacking group Fancy Bear, also known as APT28, has been exploiting a recently disclosed vulnerability in Microsoft Office, identified as CVE-2026-21509, to conduct cyber-attacks against Ukrainian and European Union organizations. The Computer Emergency Response Team of Ukraine (CERT-UA) issued a warning on February 2, detailing the exploitation of this high-severity vulnerability, which affects multiple versions of Microsoft Office, including 2016, 2019, LTSC 2021, LTSC 2024, and Microsoft 365 Apps for Enterprise.

Details of the Exploit

The first identified malicious document, titled "Consultation_Topics_Ukraine(Final).doc," was found on January 29, just days after Microsoft disclosed the vulnerability on January 26. The document was linked to discussions by the Committee of Permanent Representatives (COREPER) of the EU regarding Ukraine. Metadata indicated that the file was created on January 27, suggesting that the exploit was pre-prepared for immediate use. CERT-UA also reported a parallel phishing campaign that targeted over 60 email addresses, primarily within Ukrainian government agencies, using a file named "BULLETEN_H.doc."

Upon opening the malicious document, a network connection to an external resource was initiated via the WebDAV protocol, leading to the download of a shortcut file containing malicious code. This code executed a series of actions, including the creation of a DLL file named "EhStoreShell.dll," which masqueraded as a legitimate Windows component, and the modification of registry paths for COM hijacking. The attackers ultimately deployed the Covenant framework, a command and control tool designed for offensive cybersecurity operations.

Broader Implications

CERT-UA has noted that the exploitation of this vulnerability is expected to increase due to delays in user updates and the implementation of recommended security measures. The organization has urged users to monitor or block network interactions with the legitimate cloud storage service Filen, which is being used by the attackers for command and control infrastructure.

Criticism & Opposition

Despite the release of patches by Microsoft for older Office versions, CERT-UA expressed skepticism regarding the speed at which these updates would be adopted by users. The organization warned that the inertia in updating software could lead to a surge in cyber-attacks exploiting this vulnerability.

Official Statements

CERT-UA emphasized the urgency of implementing the mitigation measures outlined in Microsoft's advisory, particularly concerning Windows registry configurations. Microsoft confirmed the detection of exploitation attempts in the wild and urged users to ensure that their Office applications are updated.

Verbatim Quotes

  • “Given the likely delay (or inability) of users to update Microsoft Office or apply recommended security measures, the number of cyber-attacks exploiting this vulnerability is expected to increase,” — CERT-UA
  • “It is obvious that in the near future, including due to the inertia of the process or impossibility of users updating the Microsoft Office suite and/or using recommended protection mechanisms, the number of cyberattacks using the described vulnerability will begin to increase,” — CERT-UA

This ongoing situation highlights the critical need for timely software updates and robust cybersecurity practices, particularly in the face of sophisticated threats from groups like Fancy Bear.