Technadu
APT28's Operation MacroMaze: Macro Malware Campaign Targets Europe
First seen 24 Feb 2026, 16:13 UTC
•

•60.0
Export
Article Content
Browse articles
APT28, a Russia-linked advanced persistent threat group, conducted a cyberespionage campaign named Operation MacroMaze from September 2025 to January 2026. The campaign involved deploying macro malware embedded in Microsoft Office documents and utilized webhook-based methods for command-and-control communications and data exfiltration, affecting various entities across Western and Central Europe.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2025-09-01
Operation MacroMaze campaign began
2026-01-31
Operation MacroMaze campaign ended
2026-02-24
Articles published detailing the campaign
More articles in this cluster
Continue Reading
APT28 Exploits MSHTML Zero-Day Vulnerability in Windows
APT28 Exploits Zimbra Vulnerability in Ongoing Attacks Against Ukraine
GRU Compromises Home Routers in 23 States to Steal Outlook Credentials
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Critical RCE Vulnerability in Zimbra Exploited by Attackers
Widespread DNS Poisoning Campaign Targets Hotel Wi-Fi to Steal Credentials