Russian hackers target European companies with new spear phishing cyberattacks


  • APT28 (Fancy Bear) reportedly running “Operation MacroMaze” since September 2025
  • Spear phishing emails containing macro-laden Word documents used to remove information thieves
  • Attack chain relies on simple scripts and HTML, maximizing stealth and persistence

APT28, the infamous Russian state-sponsored hacking group, also known as Fancy Bear, or Sofacy, has been observed targeting “specific entities” in Western and Central Europe with information stealers.

In a recently published report, security researchers Lab52 from S2 Grupo detailed “Operation MacroMaze”, which took place from at least late September 2025 to January 2026.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top