[ << ALL_FEED ]

Infiltrate the office through Office

More in General

Breaching the office through Office 👨‍💻

The PT ESC cyber intelligence team has recorded the first phishing campaign exploiting CVE-2026-21509, targeting Russian organizations. The attackers distribute RTF documents disguised as business correspondence (screenshots 1–2).

Embedded within the RTF document is an OLE object with CLSID EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B (Shell.Explorer.1). The object’s data is packed into an OLE storage; the CONTENTS stream contains a specially crafted .lnk shortcut pointing to a remote resource (screenshot 3):

\\rostransnadzor.digital@SSL\svn\58\АКТ проверки транспортного средства.lnkCode language: plaintext (plaintext)

The @SSL suffix activates the Windows WebDAV redirector (WebClient service), turning a regular UNC request into an HTTPS request to an external server.

CVE-2026-21509 here serves as a mechanism for bypassing Microsoft Office’s built-in protections when processing OLE components. The vulnerability allows creating a COM object and accessing the remote .lnk immediately upon opening the document, thereby triggering the next stage of the attack.

🚮 At the time of research, the remote shortcut was already unavailable, so the second stage could not be fully reproduced.

Analysis of the domain rostransnadzor.digital revealed that its SOA record (the RNAME field) contains the contact e-mail gjegoshcappaniesh@gmail.com
— this same e-mail previously appeared in domains used in attacks by the BoTeam group (screenshot 4). Additionally, the repetition of characteristic artifacts points to a possible link to the group: the identical name of the malicious files “АКТ проверки транспортного средства” (screenshots 5–6), as well as the use of a similar domain name rostransnnadzor.ru.

This allows us to suggest that the campaign exploiting CVE-2026-21509 may be the work of the BoTeam hacker group 🥷

To minimize risks, we recommend updating Microsoft Office to the patched version as soon as possible. If an immediate update is not possible, as a temporary measure you should block the activation of the vulnerable OLE component Shell.Explorer.1 (CLSID EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B).

1️⃣ You need to find or create the COM Compatibility key (the path depends on the installation type — MSI / Click-to-Run — and the system bitness 32/64-bit):

MSI 64-bit or MSI 32-bit on 32-bit Windows:
HKLM\SOFTWARE\Microsoft\Office\16.0\Common\COM Compatibility\

MSI 32-bit on 64-bit Windows:
HKLM\SOFTWARE\WOW6432Node\Microsoft\Office\16.0\Common\COM Compatibility\

C2R 64-bit or C2R 32-bit on 32-bit Windows:
HKLM\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Office\16.0\Common\COM Compatibility\

C2R 32-bit on 64-bit Windows:
HKLM\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\WOW6432Node\Microsoft\Office\16.0\Common\COM CompatibilityCode language: plaintext (plaintext)

2️⃣ Inside COM Compatibility, you need to create the subkey {EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B} and add the DWORD parameter Compatibility Flags = 0x00000400.

IoCs

rostransnadzor.digital
62.3.58.8

ea078216452f5f6d4eea27bbc062286396a5252e2c267ecc3933d05a4e38da15
2bbcbc88d04615079fa17708c62f07ccb138c19bb9ed78ae43f9172cd91931baCode language: plaintext (plaintext)

#TI #APT #Malware #Phishing #ioc
@ptescalator (X, Max)

More from ti_author

More from ti_author

More in General