Russian Threat Actor Sednit Resurfaces With Sophisticated Toolkit
ID: d9b79b14-2f5c-5106-a711-148762b414d0
STIX ID: report--d9b79b14-2f5c-5106-a711-148762b414d0
Feed Name: Dark Reading
ESET researchers report that Russia‑linked Sednit (APT28) has resumed using custom malware in 2024 espionage campaigns against Ukrainian targets, deploying two implants — BeardShell (a PowerShell‑based implant using Icedrive for C2) and a heavily modified Covenant framework — plus a SlimAgent keylogger. The group uses legitimate cloud services for command‑and‑control, frequent loader updates, and social‑engineering over messaging apps to deliver Trojanized documents, making detection and disruption more difficult.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
