Adversary Intelligence — 2026-04-09
GRU Unit 26165 Deploys Previously Undocumented PRISMEX Malware Suite Against Ukraine and NATO Allies
GRU-linked APT28 (Forest Blizzard) launched a spear-phishing campaign deploying a previously undocumented malware suite dubbed PRISMEX against Ukraine and NATO's logistics partners. The campaign, active since September 2025, targets Ukrainian government agencies, defense organizations, and rail/maritime logistics in Poland, Romania, Slovenia, Turkey, Slovakia, and the Czech Republic. PRISMEX uses
Analysis
The targeting of NATO's logistics partners maps directly to Ukraine's supply lines: rail in Poland, maritime in Romania and Turkey, ammunition support in Slovakia and Czech Republic. CVE-2026-21509 exploitation without user interaction lowers the barrier to mass compromise. Combined with the parallel router hijacking campaign, GRUUnit 26165 is operating at a tempo suggesting wartime tasking priorities.
The targeting of NATO's logistics partners maps directly to Ukraine's supply lines: rail in Poland, maritime in Romania and Turkey, ammunition support in Slovakia and Czech Republic. CVE-2026-21509 exploitation without user interaction lowers the barrier to mass compromise. Combined with the parallel router hijacking campaign, GRU