logo

APT28 Operation Phantom Net Voxel: BeardShell & Covenant

ID: 672f0e16-e6f7-5177-89da-d1b5731ded9f

STIX ID: report--672f0e16-e6f7-5177-89da-d1b5731ded9f

Feed Name: Sekoia.com

Threat Score
90/100

Date Published: 2025-09-16

Date Updated: 2026-07-20

...
...

Sekoia.io TDR describes a sophisticated APT28 campaign targeting Ukrainian military administrative personnel using Signal-delivered weaponized Office documents. The infection chain uses VBA macros to install a proxy COM DLL that extracts AES-encrypted shellcode from PNG images, initializes the CLR to load a Covenant Grunt stager communicating via Koofr, and ultimately enables deployment of a BeardShell backdoor (icedrive C2) and SlimAgent spyware; the report includes detailed technical analysis, IOCs (hashes, YARA rules), and scripts to detect or decrypt artefacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.