Desk live·
ForensicPost
Nation-state/Espionage/File 26-0130

Pawn Storm Opened 2026 With an Office Zero-Day Against Ukraine and Partners

Activity attributed to the Russia-aligned group tracked as Pawn Storm opened 2026 with an Office zero-day, pressed against Ukraine and its partners. The continuity of the target list is the point.

Constructed geometry · not a chart of case data
JurisdictionUkrainethe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetGovernment, defence and aid bodies
ActorPawn Storm
D. Kennedy9 min readConfidence: medium1 source reviewed

Threat research covering the first half of 2026 describes the Russia-aligned group tracked as Pawn Storm opening the year with an Office zero-day and continuing operations against Ukraine and its partners across government, defence and wartime-aid organisations.

The zero-day attracts the attention. The target list is the more durable finding, because it has not meaningfully changed in years.

Wartime Aid Is A Soft, High-Value Target

Government and defence organisations in this category expect to be targeted and are resourced accordingly. Aid organisations supporting a conflict frequently are not: they are smaller, staffed by people focused on delivery, and hold logistics information — routes, schedules, quantities, recipients — of direct operational value.

They also sit inside the trust network of the better-defended organisations, corresponding regularly with ministries and defence bodies. That makes them attractive both for what they hold and for whom they can credibly email.

The Document Is Still The Delivery Mechanism

It is worth noting how unremarkable the technique remains. Two decades after the office document became the standard route into an organisation, a zero-day in a document format is still worth spending against government targets.

The reason is unchanged: the recipients must open documents from outside their organisation, because that is the job. No control removes that requirement, which is why this category of exposure persists through every generation of defensive tooling.

How we reported this

Compiled from published threat research, listed below. Group naming follows the research vendor’s cluster; a vendor cluster name is not an attribution to a government, and we do not treat it as one. Corrections: corrections@forensicpost.com.

Sources
  1. TrendAI reports nation-state activity in H1 2026 APT activity roundupTrend Micro
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary