APT28’s MacroMaze Targets European Entities
In a recently identified campaign, the Russia-linked threat actor known as APT28 has deployed MacroMaze malware to compromise entities across Western and Central Europe. The campaign, which took place from September 2025 to January 2026, was reported by the S2 Grupo’s LAB52 threat intelligence team. They revealed that Operation MacroMaze targets entities using webhook-based macro malware, leveraging basic tools alongside legitimate services to infiltrate systems.
The malicious operation underscores the persistent threat posed by state-sponsored cyber actors. Analysts believe these activities reflect a broader strategy to destabilize European infrastructure and gather sensitive information. The use of macro malware indicates a shift towards exploiting common business practices to penetrate defenses. Entities in the region are advised to review their cybersecurity measures and remain vigilant against such sophisticated cyber threats. For more detailed insights and to stay informed about the evolving landscape, visit the full report on The Hacker News.
https://thehackernews.com/2026/02/apt28-targeted-european-entities-using.html
