Russian hackers attack European firms with new spear-phishing cyberattacks


  • APT28 (Fancy Bear) has reportedly been running “Operation MacroMaze” since September 2025
  • Spear phishing emails with macro-filled Word documents are used to drop info thieves
  • The attack chain relies on simple scripts and HTML, maximizing stealth and persistence

APT28, the notorious Russian state-sponsored hacking group also known as Fancy Bear or Sofacy, has been observed targeting “specific entities” in Western and Central Europe with info stealers.

In a recently published report, security researchers Lab52 from S2 Grupo described “Operation MacroMaze”, which has been ongoing since at least late September 2025 to January 2026.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top