logo

Russian military hackers revive advanced malware to spy on Ukraine, researchers say

ID: eda7157b-26e5-5e2f-9938-8873cf1f7f44

STIX ID: report--eda7157b-26e5-5e2f-9938-8873cf1f7f44

Feed Name: The Record from Recorded Future News

Threat Score
88/100

Date Published: 2026-03-10

Date Updated: 2026-05-01

...
...

ESET reports that Russian state-linked APT28 (aka Fancy Bear) has reemerged since April 2024 with a refreshed espionage toolkit—notably BeardShell and a heavily modified Covenant C2—often used alongside SlimAgent (an updated Xagent keylogger) to conduct long-term surveillance of Ukrainian military personnel and other regional targets; researchers also observed exploitation of a Microsoft Office vulnerability targeting maritime, transportation and diplomatic entities across multiple countries, with activity continuing into 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.