logo

Russian Threat Actor Sednit Resurfaces With Sophisticated Toolkit

ID: d9b79b14-2f5c-5106-a711-148762b414d0

STIX ID: report--d9b79b14-2f5c-5106-a711-148762b414d0

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-03-10

Date Updated: 2026-04-21

Author: Jai Vijayan

...
...

ESET researchers report that Russia‑linked Sednit (APT28) has resumed using custom malware in 2024 espionage campaigns against Ukrainian targets, deploying two implants — BeardShell (a PowerShell‑based implant using Icedrive for C2) and a heavily modified Covenant framework — plus a SlimAgent keylogger. The group uses legitimate cloud services for command‑and‑control, frequent loader updates, and social‑engineering over messaging apps to deliver Trojanized documents, making detection and disruption more difficult.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.