CERT-UA Issues Danger Bulletin as APT28 Exploits CVE-2026-21509 Against Ukraine and EU Governments

Ukraine's Computer Emergency Response Team (CERT-UA) has issued a "Danger Bulletin" warning that APT28 (tracked as UAC-0001) is actively exploiting CVE-2026-21509 in cyberattacks targeting Ukrainian central government bodies and EU organizations — just one day after Microsoft published the vulnerability disclosure.

60+ Ukrainian Government Targets

On January 29, 2026, CERT-UA identified a phishing campaign impersonating the Ukrhydrometeorological Center, distributing a malicious document "BULLETEN_H.doc" to more than 60 email addresses belonging primarily to Ukrainian central executive bodies. A separate lure document — "Consultation_Topics_Ukraine(Final).doc" — was crafted around EU COREPER consultations on the situation in Ukraine, with metadata showing creation on January 27, just one day after Microsoft's advisory.

COM Hijacking and Covenant C2

Opening the weaponized document triggers a WebDAV connection that downloads a shortcut file containing code to fetch an executable payload. The infection chain creates a malicious DLL (EhStoreShell.dll) disguised as an Enhanced Storage Shell Extension, a shellcode-laden image file (SplashScreen.png), and implements COM hijacking via registry modification of CLSID {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. A scheduled task "OneDriveHealth" ensures persistence by restarting explorer.exe, which loads the hijacked DLL and executes the Covenant C2 framework.

Notably, APT28's Covenant deployment uses the legitimate Filen cloud storage service (filen.io) as its C2 infrastructure — a technique designed to blend malicious traffic with legitimate cloud communications.

Rapid EU Expansion

CERT-UA identified three additional exploit documents targeting EU country organizations in late January, with one attack domain registered the same day it was used (January 30). The bulletin warned that the number of attacks leveraging CVE-2026-21509 will increase due to the inherent delay in users updating Microsoft Office. CERT-UA recommended immediately applying Microsoft's registry mitigations and blocking or monitoring network connections to Filen cloud infrastructure.

Read the full analysis on IntelFusions