← Back to Feed

Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities

March 26, 2026 · Trend Micro · Severity: CRITICAL

This blog discusses the steganography, cloud abuse, and email-based backdoors used against the Ukrainian defense supply chain in the latest Pawn Storm campaign that TrendAI™ Research observed and analyzed.

Key Takeaways

  • The Pawn Storm campaign deploys PRISMEX malware using steganography and cloud abuse.
  • The campaign targets the Ukrainian defense supply chain.
  • Email-based backdoors are used alongside steganography in the Pawn Storm operation.
☕ Buy a Coffee