New APT28 Attack Via Signal Messenger Delivers BeardShell and Covenant Malware
ID: 4b10d73f-f42b-54a9-b1a0-0339cec6830e
STIX ID: report--4b10d73f-f42b-54a9-b1a0-0339cec6830e
Feed Name: cybersecurityNews.com
Threat Score
Late-summer 2025 researchers uncovered “Phantom Net Voxel,” a sophisticated APT28 spearphishing campaign targeting Ukrainian military personnel via Signal; malicious Office macros install a DLL/PNG pair that uses steganography to extract shellcode, deploy Covenant HTTP Grunt and a custom BeardShell backdoor, and use Koofr/icedrive cloud storage for encrypted C2, persisting via registry and COM registration (CLSID {2227A280-3AEA-1069-A2DE-08002B30309D}).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
