An India-linked espionage campaign exploited CVE-2026-21509, a Microsoft Office security feature bypass in OLE object handling, to target Pakistani government entities, with Sindh Integrated Emergency & Health Services (SIEHS) identified as a primary victim. Breakglass Intelligence said the attackers used weaponized RTF, OLE, and DOCX files themed around ambulance surveillance procurement to deliver payloads with little or no user interaction beyond opening or previewing the document. The malicious files embedded Shell.Explorer.1 or WebBrowser ActiveX objects and abused an OLE ObjectPool stream containing a crafted Shell Link to retrieve LNK or ClickOnce payloads over WebDAV or HTTPS, bypassing Office OLE mitigations and avoiding macros.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
The April report concluded the activity was distinct from previously reported Eastern Europe-focused exploitation and represented the first documented South Asian state-sponsored use of CVE-2026-21509. It also revealed test artifacts including an internal WebDAV server address and a mistyped payload path, indicating operational security mistakes.
Breakglass documented a separate cluster of exploit documents containing Chinese-language metadata, creator qb.li, and WPS Cloud identifiers. The finding suggested either a shared exploit builder across actors or separate adoption of the same technique by a Chinese-speaking operator.
A later Breakglass report described a wider state-sponsored espionage campaign exploiting CVE-2026-21509 against Pakistani government entities, with SIEHS identified as the primary victim. The report assessed the activity with medium-high confidence as India-linked and potentially associated with groups such as SideWinder, Confucius, or Patchwork.
Breakglass Intelligence reported developer metadata including MALDEV01, WarMachine, WPS Office artifacts, and English-India locale markers, assessing the sample was likely tied to a distinct South Asian APT or shared exploit builder rather than direct APT28 activity. The report also noted poor detections across antivirus and sandbox products.
The exploit chain delivered ClickOnce or LNK payloads from sbis.psca.gop.pk, a compromised Punjab Safe Cities Authority government subdomain with a valid TLS certificate. Breakglass reported this legitimate Pakistani government infrastructure gave the operation trust and reputation advantages.
A malicious Word 97-2003 document exploiting CVE-2026-21509 was created to target Sindh Integrated Emergency & Health Services procurement personnel in Pakistan using an ambulance surveillance procurement theme. The document used embedded OLE content to retrieve a malicious payload with little or no user interaction beyond opening or previewing the file.
A GitHub repository titled "Ashwesker-CVE-2026-21509" was published, indicating public release of code or proof-of-concept material related to CVE-2026-21509 shortly after Microsoft's disclosure. This represents a new technical development that could aid broader analysis or weaponization of the flaw.
Microsoft disclosed and patched CVE-2026-21509 on 2026-01-26, describing it as a Microsoft Office zero-day that was already being exploited in the wild via malicious Office documents. Reporting cited exploitation through the Shell.Explorer.1 COM/OLE object to invoke the legacy Internet Explorer engine and execute attacker-controlled LNK payloads.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
intel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourcegithub.com
Open sourcedecalage.info
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.