APT28 Weaponizes CVE-2026-21509 Zero-Day in Operation Neusploit Targeting Eastern Europe

Zscaler ThreatLabz has uncovered a new campaign dubbed Operation Neusploit, attributed with high confidence to Russia-linked threat group APT28 (Fancy Bear), which weaponized the freshly patched CVE-2026-21509 vulnerability in Microsoft RTF files to target countries across Central and Eastern Europe.

Zero-Day to N-Day in Three Days

Microsoft released an out-of-band update to address CVE-2026-21509 on January 26, 2026. ThreatLabz observed active in-the-wild exploitation just three days later on January 29 — a strikingly narrow window that underscores APT28's ability to rapidly operationalize vulnerabilities. Targets included organizations in Ukraine, Slovakia, and Romania.

Multi-Stage Infection Chain

The attack begins with specially crafted RTF files exploiting CVE-2026-21509, which download a malicious dropper DLL from actor-controlled servers. ThreatLabz identified two variants of the attack chain deploying distinct payloads:

Server-Side Geofencing

APT28 employed sophisticated server-side evasion techniques, delivering the malicious DLL payload only when requests originated from the targeted geographic region and included the correct User-Agent HTTP header. This geofencing approach ensures that security researchers and sandboxes outside the target zone receive benign responses, significantly complicating analysis.

Social engineering lures were crafted in both English and localized languages — Romanian, Slovak, and Ukrainian — demonstrating deliberate effort to tailor attacks to specific national audiences. ThreatLabz stated it is actively collaborating with Microsoft as monitoring of Operation Neusploit continues.

Read the full analysis on IntelFusions