logo

New APT28 Attack Via Signal Messenger Delivers BeardShell and Covenant Malware

ID: 4b10d73f-f42b-54a9-b1a0-0339cec6830e

STIX ID: report--4b10d73f-f42b-54a9-b1a0-0339cec6830e

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-09-16

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Late-summer 2025 researchers uncovered “Phantom Net Voxel,” a sophisticated APT28 spearphishing campaign targeting Ukrainian military personnel via Signal; malicious Office macros install a DLL/PNG pair that uses steganography to extract shellcode, deploy Covenant HTTP Grunt and a custom BeardShell backdoor, and use Koofr/icedrive cloud storage for encrypted C2, persisting via registry and COM registration (CLSID {2227A280-3AEA-1069-A2DE-08002B30309D}).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.