IGMPI facebook Highly Active Threat Group UAC-0001 Deploys Malware via Office Documents
IGMPI Logo
Centre for Cyber Forensic and Cyber Security

(An Autonomous Body Recognized by Ministry of Commerce & Industry, Government of India)

Competency based placement focussed Education | Training | Research | Consultancy

18001031071 (Toll Free), +91 11 26512850
Regular | Part-time (Online Live Classes) Modes
Highly Active Threat Group UAC-0001 Deploys Malware via Office Documents

Highly Active Threat Group UAC-0001 Deploys Malware via Office Documents

Security researchers reported that a zero-day vulnerability in Microsoft Office (CVE-2026-21509) was actively exploited to deliver malicious payloads — including backdoors and espionage tools through crafted Office documents. The exploited flaw bypassed traditional Object Linking and Embedding (OLE) mitigations, allowing attackers to trigger code execution when users opened poisoned files. Federal cybersecurity agencies added this flaw to known exploited vulnerabilities catalogs, urging rapid patch deployment. This development underscores the enduring importance of layered defenses  such as behavior-based detection and macro restrictions — even as adversaries refine their techniques

26-01-2026