APT28's 'Operation MacroMaze': A Persistent Cyber Espionage Campaign Targeting Western Europe
APT28's 'Operation MacroMaze' employs spear-phishing and sophisticated malware to infiltrate Western European entities, highlighting the evolving nature of cyber espionage.
Encrygma is selling the entire Full Cyber Weapon Research of APT28's 'Operation MacroMaze': A Persistent Cyber Espionage Campaign Targeting Western Europe for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- Medium
- Actor Type:
- APT
- Geography:
- Western Europe
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Executive Summary
Between late September 2025 and January 2026, Russian state-sponsored hacking group APT28, also known as Fancy Bear or Sofacy, conducted a cyber-espionage campaign dubbed "Operation MacroMaze." This operation targeted Western and Central European entities, employing spear-phishing emails with diplomatic themes to deceive recipients into enabling malicious macros in Microsoft Word documents. Once activated, the malware established persistence, gathered system data, and exfiltrated it via auto-submitting HTML forms. The campaign's effectiveness was attributed to its technical simplicity and the attackers' use of basic tools—batch files, VBS launchers, and HTML—organized to evade detection by performing tasks in hidden browser sessions, cleaning up artifacts, and outsourcing delivery and exfiltration to common webhook services. (techradar.com)
Background
APT28 has a long history of cyber-espionage operations, often targeting entities of strategic interest to Russian state objectives. The group's activities have previously included operations against Ukrainian entities and other European targets. The "Operation MacroMaze" campaign represents a continuation of this trend, with a focus on Western and Central European organizations.
Technical Details
The spear-phishing emails employed in "Operation MacroMaze" were highly personalized, often related to diplomatic themes. In one instance, the researchers observed a slightly altered copy of official diplomatic agendas being distributed. The emails contained Microsoft Word documents with malicious macros. Once the macros were enabled by the recipient, the malware did not deliver a single payload but instead dropped multiple small scripts and HTML templates. These components worked together to establish persistence, gather system data, and exfiltrate it via auto-submitting HTML forms. The attackers utilized basic tools—batch files, VBS launchers, and HTML—to perform tasks in hidden browser sessions, clean up artifacts, and outsource delivery and exfiltration to common webhook services. This approach allowed the campaign to evade detection and maintain a low profile. (techradar.com)
Implications
The "Operation MacroMaze" campaign underscores the evolving nature of cyber espionage. The use of spear-phishing emails with diplomatic themes and the deployment of multiple small scripts and HTML templates for malware delivery and exfiltration highlight a shift towards more sophisticated and persistent attack methods. The campaign's effectiveness, despite its technical simplicity, suggests that threat actors are continually refining their tactics to evade detection and achieve their objectives.
Recommendations
Organizations in Western and Central Europe should remain vigilant against spear-phishing attacks, particularly those involving diplomatic themes. Implementing robust email filtering solutions, conducting regular security awareness training for employees, and maintaining up-to-date security patches are essential measures to mitigate the risk of such attacks. Additionally, monitoring network traffic for unusual activities and employing advanced threat detection systems can help identify and respond to potential intrusions promptly.
Conclusion
APT28's "Operation MacroMaze" serves as a reminder of the persistent and evolving nature of cyber espionage. Organizations must adopt a proactive and multi-layered approach to cybersecurity to defend against such sophisticated threats effectively.
Highlights:
- Russian hackers target European firms with new spear-phishing cyberattacks, Published on Tuesday, February 24
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



