Threat research covering the first half of 2026 describes the Russia-aligned group tracked as Pawn Storm opening the year with an Office zero-day and continuing operations against Ukraine and its partners across government, defence and wartime-aid organisations.
The zero-day attracts the attention. The target list is the more durable finding, because it has not meaningfully changed in years.
Wartime Aid Is A Soft, High-Value Target
Government and defence organisations in this category expect to be targeted and are resourced accordingly. Aid organisations supporting a conflict frequently are not: they are smaller, staffed by people focused on delivery, and hold logistics information — routes, schedules, quantities, recipients — of direct operational value.
They also sit inside the trust network of the better-defended organisations, corresponding regularly with ministries and defence bodies. That makes them attractive both for what they hold and for whom they can credibly email.
The Document Is Still The Delivery Mechanism
It is worth noting how unremarkable the technique remains. Two decades after the office document became the standard route into an organisation, a zero-day in a document format is still worth spending against government targets.
The reason is unchanged: the recipients must open documents from outside their organisation, because that is the job. No control removes that requirement, which is why this category of exposure persists through every generation of defensive tooling.
Compiled from published threat research, listed below. Group naming follows the research vendor’s cluster; a vendor cluster name is not an attribution to a government, and we do not treat it as one. Corrections: corrections@forensicpost.com.