logo

APT28 hackers use Signal chats to launch new malware attacks on Ukraine

ID: 6d962f21-97ec-55d2-9082-7722eaf91028

STIX ID: report--6d962f21-97ec-55d2-9082-7722eaf91028

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2025-06-23

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

APT28 (UAC-0001) abused Signal to spear-phish Ukrainian government targets, delivering a malicious document that deploys a Covenant loader which retrieves BeardShell (a C++ backdoor that executes chacha20-poly1305-encrypted PowerShell scripts via Icedrive API) and SlimAgent (a screenshot grabber encrypting images with AES/RSA). Persistence is achieved through COM-hijacking in the Windows registry; CERT-UA and ESET investigations linked active exploitation and recommend monitoring app.koofr.net and api.icedrive.net for related activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.