IOC Radar
TLP:WHITE6 IOCs

APT28: Geofencing as a Targeting Signal (CVE-2026-21509 Campaign)

SS
Synaptic Systems
Published February 3, 2026Original Report

Threat Actors

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYAPT28INFRASTRUCTUREunknownCAPABILITYunknownVICTIMunknown
Adversary(1)
Infrastructure
Capability
Victim

Attack Flow6 steps · MITRE ATT&CK mapped

Initial AccessTA0001·T1190
1/6
Exploit Public-Facing Application
ActionExploit Office vulnerability
APT28 leverages CVE-2026-21509, a vulnerability in Microsoft Office, as an initial access vector.

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise6

TypeIndicatorConfidenceScoreFirst Seen
SHA256fd3f13db41cd5b442fa26ba8bc0e9703ed243b3516374e3ef89be71cbf07436b
file-hashindicatorintel-blog
Medium
53
Jun 2, 26
SHA256b2ba51b4491da8604ff9410d6e004971e3cd9a321390d0258e294ac42010b546
file-hashindicatorintel-blog
Medium
53
Jun 2, 26
SHA2565a17cfaea0cc3a82242fdd11b53140c0b56256d769b07c33757d61e0a0a6ec02
file-hashindicatorintel-blog
Medium
53
Jun 2, 26
SHA256969d2776df0674a1cca0f74c2fccbc43802b4f2b62ecccecc26ed538e9565eae
file-hashindicatorintel-blog
Medium
53
Jun 2, 26
CVECVE-2026-21509
aptespionageexploit
Medium
54
Jun 2, 26
SHA256c91183175ce77360006f964841eb4048cf37cb82103f2573e262927be4c7607f
file-hashindicatorintel-blog
Medium
53
Jun 2, 26

IOC Relationship Graph

IOC Relationship Graph6 total IOCs
SHA256CVE
SHA2565CVE1Actors1REPORTAPT28: Geofencing as a TarAPT28
scroll to zoom · drag to pan · click IOC to open