APT28 hackers use Signal chats to launch new malware attacks on Ukraine
ID: 6d962f21-97ec-55d2-9082-7722eaf91028
STIX ID: report--6d962f21-97ec-55d2-9082-7722eaf91028
Feed Name: Bleeping Computer
APT28 (UAC-0001) abused Signal to spear-phish Ukrainian government targets, delivering a malicious document that deploys a Covenant loader which retrieves BeardShell (a C++ backdoor that executes chacha20-poly1305-encrypted PowerShell scripts via Icedrive API) and SlimAgent (a screenshot grabber encrypting images with AES/RSA). Persistence is achieved through COM-hijacking in the Windows registry; CERT-UA and ESET investigations linked active exploitation and recommend monitoring app.koofr.net and api.icedrive.net for related activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
