PRISMEX is a multi-component malware suite attributed with high confidence to the Russian state-aligned espionage group APT28, also known as Fancy Bear, Pawn Storm, Forest Blizzard, and UAC-0001. It has been used since at least September 2025 in campaigns targeting Ukraine’s defense supply chain, government and emergency services, hydrometeorological organizations, transport and logistics infrastructure, and allied support networks across Central and Eastern Europe, including countries involved in military aid and ammunition initiatives.
The suite is designed for stealthy intrusion, espionage, and command-and-control, with evidence of potential sabotage functionality. Reported components include PrismexSheet, PrismexDrop, PrismexLoader, and PrismexStager. Infection chains associated with PRISMEX used themed spearphishing lures and malicious Office documents, including RTF and Excel files, to exploit Microsoft Office and Windows vulnerabilities such as CVE-2026-21509 and likely CVE-2026-21513. Earlier stages used VBA macros, self-reading document logic, and decoy content tailored to military logistics and aid operations.
PRISMEX employs several defense-evasion and execution techniques, notably steganographic payload concealment, COM hijacking for persistence and execution, fileless in-memory loading, and abuse of legitimate cloud services for command-and-control. PrismexLoader extracts hidden payloads from image data using a custom Bit Plane Round Robin steganographic method and hosts the .NET CLR inside a trusted process to load assemblies directly from memory. PrismexStager is based on the Covenant Grunt framework and supports encrypted cloud-mediated command-and-control. Additional persistence mechanisms include scheduled tasks and COM object hijacking.
The malware has been assessed as an evolution related to the NotDoor ecosystem and reflects APT28 tradecraft focused on covert access to operational support networks rather than only frontline military entities. Beyond espionage, at least one observed campaign included a destructive wiper command capable of deleting user files, indicating that PRISMEX can support disruptive or sabotage-oriented objectives in addition to intelligence collection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-21513 resides in the logic responsible for handling hyperlink navigation within ieframe.dll (Internet Explorer frame). CVE-2026-21513 was exploited as a zero-day vulnerability. The exploit sample was first submitted to VirusTotal on January 30, 2026. This was 11 days before Microsoft released the patch on February 10, 2026. | TrendAI Research identified a series of interconnected malware components collectively referred to as "PRISMEX," named for its steganographic characteristic of distributing the payload across the entire image. It is comprised of a dropper (PrismexDrop), a steganography loader (PrismexLoader), and a Covenant Grunt implant (PrismexStager).
Pawn Storm’s campaign in late January 2026 exploited the Microsoft Office vulnerability CVE-2026-21509 to target government, military, and critical infrastructure entities across Central and Eastern Europe. The PRISMEX campaign’s initial access vector relies on the weaponization of CVE-2026-21509, a security feature bypass vulnerability in the Microsoft Office Object Linking and Embedding (OLE) mechanism. | TrendAI Research identified a series of interconnected malware components collectively referred to as "PRISMEX," named for its steganographic characteristic of distributing the payload across the entire image. It is comprised of a dropper (PrismexDrop), a steganography loader (PrismexLoader), and a Covenant Grunt implant (PrismexStager).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TrendAI Research identified a series of interconnected malware components collectively referred to as "PRISMEX," named for its steganographic characteristic of distributing the payload across the entire image. It is comprised of a dropper (PrismexDrop), a steganography loader (PrismexLoader), and a Covenant Grunt implant (PrismexStager).
Trend Micro said the actor ... has been using a collection of malware components known as "Prismex" to target the defense supply-chain of Ukraine and its allies ... "Prismex combines advanced steganography, component object model (COM) hijacking, and legitimate cloud service abuse for command and control," ... The special malware includes both espionage and sabotage capabilities, with the latter including wiper commands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
A hidden scheduled task ("OneDriveHealth") runs once, one minute after infection, executing a command sequence that terminates and restarts explorer.exe.
MITRE ATT&CK mapping Tactic Technique Initial Access T1566.001 - Spearphishing Attachment Execution T1059.001 - PowerShell
PrismexSheet: A malicious Excel dropper with VBA macros that extracts payloads embedded within the file itself using steganography techniques.
The attached malicious RTF document triggers CVE-2026-21509 upon opening. This bypasses OLE security restrictions, forcing the Shell.Explorer.1 object to browse a remote WebDAV share and automatically execute a malicious shortcut (.lnk) file contained therein.
A hidden scheduled task ("OneDriveHealth") runs once, one minute after infection, executing a command sequence that terminates and restarts explorer.exe.
MITRE ATT&CK mapping ... Defense Evasion ... T1055 - Process Injection
These components are designed to evade modern Endpoint Detection and Response (EDR) systems through "fileless" execution, advanced steganography, and abuse of legitimate cloud services.
This component masquerades as the legitimate Windows DLL like EhStorShell.dll.
The final component, PrismexStager, connects to command-and-control servers via Filen.io cloud services. This helps attackers blend malicious traffic with normal encrypted communications, making detection harder while enabling data exfiltration and remote control.
Victims who open the attached RTF file trigger exploitation of CVE-2026-21509, which bypasses security controls and forces the system to connect to an attacker-controlled WebDAV server. This automatically retrieves and executes a malicious LNK file without further user interaction.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular malware suite used by Pawn Storm that employs fileless execution, steganography, COM hijacking persistence, and abuse of legitimate cloud services. Components include an Excel macro dropper, a native dropper, a proxy DLL loader that extracts payloads from PNG images, and a Covenant-based stager for command-and-control.
A malware suite used in a spear-phishing campaign attributed to APT28. It includes a dropper, loader, and Covenant-based implant, supports fileless attacks, and uses encrypted command-and-control communications via cloud services such as Filen.io for espionage and persistent access.
A malware framework/component set used by APT28/Pawn Storm for espionage and sabotage. It uses steganography, COM hijacking, and legitimate cloud services for C2, and includes wiper functionality.
A modular malware suite used for espionage and command-and-control. It includes components for payload decryption and persistence, in-memory loading, steganographic payload extraction, COM hijacking, abuse of Filen.io for encrypted C2, and fileless execution to maintain stealthy long-term access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.