logo

APT28 conducts long-term espionage on Ukrainian forces using custom malware

ID: c53d971d-61b5-582c-974a-d632b5d974ac

STIX ID: report--c53d971d-61b5-582c-974a-d632b5d974ac

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-03-10

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

ESET and other researchers attribute a sustained espionage campaign since April 2024 to Russia-linked APT28 (Sednit/Fancy Bear), which deployed paired custom implants—BEARDSHELL and COVENANT—alongside SLIMAGENT/XAgent-derived tools to maintain persistent access to Ukrainian military systems, exfiltrate data via legitimate cloud services (Icedrive, Filen), and employ advanced obfuscation and encryption techniques indicative of a sophisticated nation-state operation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.