216.73.217.98

Operation MacroMaze: New APT28 Campaign Using Basic Tooling and Legitimate Infrastructure

· Published 16/02/2026 14:28 · Modified 17/02/2026 16:08

Export JSON

Essential information

Published
16/02/2026 14:28
Modified
17/02/2026 16:08
Tags
2026-02-16 batch files droppers exfiltration fancy bear html macros operation macromaze persistence vbscript webhook
Related entities
7 observables, 1 intrusion sets (apt), 16 techniques (mitre), 2 others

Description

, attributed to APT28 (), targets entities in Western and Central Europe from September 2025 to January 2026. The campaign utilizes basic tools and legitimate services for infrastructure and data . Multiple documents with varying macro variants act as , establishing a foothold by creating files in the %USERPROFILE% folder. The attack chain involves execution, scheduled task creation for , and a multi-stage process using . is achieved through -based techniques, leveraging .site for data transmission. Despite its simplicity, the campaign demonstrates effective operational tradeoffs, making detection and attribution challenging.

External references