Russian military hackers revive advanced malware to spy on Ukraine, researchers say
ID: eda7157b-26e5-5e2f-9938-8873cf1f7f44
STIX ID: report--eda7157b-26e5-5e2f-9938-8873cf1f7f44
Feed Name: The Record from Recorded Future News
ESET reports that Russian state-linked APT28 (aka Fancy Bear) has reemerged since April 2024 with a refreshed espionage toolkit—notably BeardShell and a heavily modified Covenant C2—often used alongside SlimAgent (an updated Xagent keylogger) to conduct long-term surveillance of Ukrainian military personnel and other regional targets; researchers also observed exploitation of a Microsoft Office vulnerability targeting maritime, transportation and diplomatic entities across multiple countries, with activity continuing into 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
