Operation MacroMaze: New APT28 Campaign Using Basic Tooling and Legitimate Infrastructure
Operation MacroMaze, attributed to APT28 (Fancy Bear), targets entities in Western and Central Europe from September 2025 to January 2026. The campaign utilizes basic tools and legitimate services for infrastructure and data exfiltration. Multiple documents with varying macro variants act as droppers, establishing a foothold by creating files in the %USERPROFILE% folder. The attack chain involves VBScript execution, scheduled task creation for persistence, and a multi-stage process using batch files. Exfiltration is achieved through HTML-based techniques, leveraging webhook.site for data transmission. Despite its simplicity, the campaign demonstrates effective operational tradeoffs, making detection and attribution challenging.
Pulse ID: 699329aa6d09f10e6d85a92b
Pulse Link: https://otx.alienvault.com/pulse/699329aa6d09f10e6d85a92b
Pulse Author: AlienVault
Created: 2026-02-16 14:28:58
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APT28 #CyberSecurity #Europe #HTML #InfoSec #Mac #OTX #OpenThreatExchange #RAT #ScriptExecution #VBS #bot #AlienVault