A Russia-aligned advanced persistent threat (APT) group widely tracked as Pawn Storm has launched a highly coordinated cyber campaign targeting Ukraine and several of its allied nations. This campaign introduces a sophisticated malware ecosystem called PRISMEX, designed to infiltrate, persist, and operate silently within critical systems.
The operation focuses heavily on defense logistics, humanitarian support channels, and infrastructure tied to military coordination. Countries impacted include Poland, Romania, Czech Republic, Slovakia, Slovenia, and Turkey—regions that play a key role in supporting Ukraine.

What makes this campaign particularly concerning is the attacker’s ability to combine zero-day exploitation, steganography, and cloud-based command-and-control (C2) techniques. These methods allow the malware to blend into normal system behavior, making detection significantly harder.
Background: A Familiar but Evolving Threat Actor
Pawn Storm, also known as APT28 or Fancy Bear, has been active for over a decade. Since 2014, the group has consistently targeted Ukrainian institutions. However, the latest campaign shows a clear shift—not just toward espionage, but also toward operational disruption.
Activity tied to PRISMEX has been observed since late 2025, with a noticeable escalation in early 2026. The attackers appear to be moving faster than before, weaponizing vulnerabilities almost immediately after discovery—or even before public disclosure.
What Is PRISMEX?
PRISMEX isn’t a single piece of malware. Instead, it’s a modular toolkit made up of several components working together:
- PrismexSheet – an Excel-based dropper using macros and hidden payloads
- PrismexDrop – prepares the system and ensures persistence
- PrismexLoader – extracts hidden payloads from images using steganography
- PrismexStager – deploys a Covenant-based implant for command-and-control
This layered structure allows the attackers to remain flexible. If one component is detected, others can still function.
Attack Chain: How the Infection Happens
Step 1: Initial Delivery
The attack begins with spear-phishing emails. These messages are carefully crafted and often appear to come from trusted sources. Topics include:
- Military training invitations
- Weather alerts
- Weapon-related intelligence
The goal is simple—convince the target to open an attachment.
Step 2: Exploiting CVE-2026-21509
Once the victim opens the malicious RTF file, a vulnerability in Microsoft Office is triggered. This flaw allows attackers to bypass security controls and force the system to retrieve a malicious .lnk file from a remote server.
No extra clicks are required. Just opening the file is enough.
Step 3: Possible Zero-Day Exploitation (CVE-2026-21513)
The downloaded shortcut file may trigger another vulnerability—this time in the MSHTML framework. This allows attackers to execute code without triggering typical security warnings.
Evidence suggests this vulnerability was used as a zero-day, meaning it was exploited before a patch was available.
Step 4: Payload Deployment
After exploitation, the system connects to a command server and downloads further payloads. Two main paths have been observed:
- PRISMEX infection chain
- Alternative MiniDoor backdoor chain
Steganography: Hiding Malware in Plain Sight
One of the most interesting aspects of PRISMEX is how it hides malicious code inside images.
Instead of embedding data in a predictable way, the attackers use a method called “Bit Plane Round Robin.” This technique distributes hidden data across an entire image in multiple passes, making it extremely difficult to detect.
To a normal user—or even many security tools—the image looks completely harmless.
Persistence Through COM Hijacking
PRISMEX uses a clever persistence technique involving COM object hijacking. By modifying specific registry entries, the malware ensures it gets loaded automatically whenever Windows Explorer starts.
Because it runs inside a trusted system process, it avoids raising suspicion.
Fileless Execution and Evasion Techniques
Modern security tools often rely on detecting files written to disk. PRISMEX avoids this entirely:
- Payloads are executed directly in memory
- .NET assemblies are loaded without touching the filesystem
- Legitimate cloud services are used for communication
This makes traditional detection methods much less effective.
Command and Control via Cloud Services
Instead of using suspicious domains, PRISMEX relies on legitimate encrypted cloud storage platforms like Filen.io.
This approach allows malicious traffic to blend in with normal activity. Firewalls and security tools often allow such traffic by default, making it an ideal covert channel.
Targeting Strategy: Why These Organizations?
The campaign isn’t random. It’s carefully planned to target critical support systems:
Ukraine
- Government bodies
- Defense organizations
- Weather services
Allied Nations
- Rail logistics in Poland
- Maritime transport in Romania and Slovenia
- Defense coordination in Czech Republic and Slovakia
These sectors play a key role in maintaining supply lines and operational readiness.
Strategic Intent: Beyond Espionage
This campaign goes beyond intelligence gathering. There are clear signs of potential sabotage capabilities.
Previous activity linked to this group included commands capable of wiping entire user directories. This suggests the attackers are preparing for scenarios where disruption becomes more important than data theft.
Timeline Indicates Advanced Knowledge
One of the most alarming findings is how early the attackers prepared:
- Infrastructure was set up two weeks before vulnerability disclosure
- Exploits were used before patches were released
This strongly suggests access to insider knowledge or advanced vulnerability research capabilities.
Detection Challenges
PRISMEX is difficult to detect for several reasons:
- Uses trusted applications and services
- Executes payloads in memory
- Avoids writing suspicious files
- Blends into normal network traffic
This means organizations must shift from signature-based detection to behavior-based monitoring.
Risk Mitigation Recommendations
Organizations should take immediate steps to reduce exposure:
Patch Management
Ensure all systems are updated, especially those related to:
- Microsoft Office
- Windows components
Restrict Cloud Services
Limit access to unauthorized file-sharing platforms and enforce strict allowlists.
Disable Risky Components
If patching isn’t possible immediately, disable vulnerable COM objects like Shell.Explorer.1.
Strengthen Email Security
- Block suspicious RTF attachments
- Monitor macro activity
- Track unusual email behavior
Threat Hunting
Look for indicators such as:
- Unexpected registry modifications
- CLR activity in non-.NET processes
- Suspicious scheduled tasks
Our Expert Opinion
What stands out most in this campaign is not just the technical sophistication, but the strategic timing and intent behind it. Pawn Storm appears to be operating with a level of coordination that goes beyond typical cyber espionage. The early preparation of infrastructure, combined with rapid exploitation of vulnerabilities, suggests a well-resourced and highly organized operation.
From a broader perspective, this campaign reflects a shift in how cyber operations are being used in modern conflict. Instead of focusing purely on intelligence gathering, attackers are now targeting the systems that enable logistics, coordination, and real-world decision-making. By compromising weather data providers or transport infrastructure, even small disruptions could have significant ripple effects on military operations.
Another important takeaway is the increasing use of legitimate services as part of the attack chain. By leveraging trusted cloud platforms, attackers are effectively hiding in plain sight. This makes traditional security approaches less effective and forces organizations to rethink how they monitor network activity.
The use of steganography also highlights a growing trend toward more subtle and creative evasion techniques. Instead of relying on complex encryption alone, attackers are embedding malicious content into everyday file formats. This not only complicates detection but also raises the bar for forensic analysis.
In our view, the biggest risk is not just the current campaign, but what it represents for the future. If threat actors continue to combine zero-day exploits, fileless malware, and trusted infrastructure, the gap between attackers and defenders could widen significantly.
Organizations need to adopt a mindset that assumes compromise is possible at any time. This means focusing on detection, response, and resilience rather than prevention alone. Investing in behavioral analytics, threat intelligence, and continuous monitoring will be critical moving forward.
Ultimately, PRISMEX is a reminder that cyber threats are evolving rapidly, and defensive strategies must evolve just as quickly.
Conclusion
PRISMEX represents a major step forward in APT tradecraft. By combining stealth, speed, and strategic targeting, Pawn Storm has demonstrated its ability to adapt and innovate.
Organizations connected to defense, logistics, or humanitarian operations should consider themselves at elevated risk and act accordingly.
The key takeaway is simple: this is no longer just about data theft—it’s about disruption.
