Infiltrate the office through Office

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
Breaching the office through Office 👨💻
The PT ESC cyber intelligence team has recorded the first phishing campaign exploiting CVE-2026-21509, targeting Russian organizations. The attackers distribute RTF documents disguised as business correspondence (screenshots 1–2).
Embedded within the RTF document is an OLE object with CLSID EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B (Shell.Explorer.1). The object’s data is packed into an OLE storage; the CONTENTS stream contains a specially crafted .lnk shortcut pointing to a remote resource (screenshot 3):
\\rostransnadzor.digital@SSL\svn\58\АКТ проверки транспортного средства.lnkCode language: plaintext (plaintext)
The @SSL suffix activates the Windows WebDAV redirector (WebClient service), turning a regular UNC request into an HTTPS request to an external server.
CVE-2026-21509 here serves as a mechanism for bypassing Microsoft Office’s built-in protections when processing OLE components. The vulnerability allows creating a COM object and accessing the remote .lnk immediately upon opening the document, thereby triggering the next stage of the attack.
🚮 At the time of research, the remote shortcut was already unavailable, so the second stage could not be fully reproduced.
Analysis of the domain rostransnadzor.digital revealed that its SOA record (the RNAME field) contains the contact e-mail gjegoshcappaniesh@gmail.com
— this same e-mail previously appeared in domains used in attacks by the BoTeam group (screenshot 4). Additionally, the repetition of characteristic artifacts points to a possible link to the group: the identical name of the malicious files “АКТ проверки транспортного средства” (screenshots 5–6), as well as the use of a similar domain name rostransnnadzor.ru.
This allows us to suggest that the campaign exploiting CVE-2026-21509 may be the work of the BoTeam hacker group 🥷
To minimize risks, we recommend updating Microsoft Office to the patched version as soon as possible. If an immediate update is not possible, as a temporary measure you should block the activation of the vulnerable OLE component Shell.Explorer.1 (CLSID EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B).
1️⃣ You need to find or create the COM Compatibility key (the path depends on the installation type — MSI / Click-to-Run — and the system bitness 32/64-bit):
MSI 64-bit or MSI 32-bit on 32-bit Windows:
HKLM\SOFTWARE\Microsoft\Office\16.0\Common\COM Compatibility\
MSI 32-bit on 64-bit Windows:
HKLM\SOFTWARE\WOW6432Node\Microsoft\Office\16.0\Common\COM Compatibility\
C2R 64-bit or C2R 32-bit on 32-bit Windows:
HKLM\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Office\16.0\Common\COM Compatibility\
C2R 32-bit on 64-bit Windows:
HKLM\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\WOW6432Node\Microsoft\Office\16.0\Common\COM CompatibilityCode language: plaintext (plaintext)
2️⃣ Inside COM Compatibility, you need to create the subkey {EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B} and add the DWORD parameter Compatibility Flags = 0x00000400.
IoCs
rostransnadzor.digital
62.3.58.8
ea078216452f5f6d4eea27bbc062286396a5252e2c267ecc3933d05a4e38da15
2bbcbc88d04615079fa17708c62f07ccb138c19bb9ed78ae43f9172cd91931baCode language: plaintext (plaintext)
#TI #APT #Malware #Phishing #ioc
@ptescalator (X, Max)





More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



