logo

APT28 Uses BEARDSHELL and COVENANT Malware to Spy on Ukrainian Military

ID: 17c420c5-006e-546a-8c24-347923770b38

STIX ID: report--17c420c5-006e-546a-8c24-347923770b38

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-03-10

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

ESET analysis describes APT28 (a Russian GRU-linked group) deploying BEARDSHELL, COVENANT, and SLIMAGENT since 2024 to conduct long-term surveillance of Ukrainian military targets; the report highlights malware capabilities (keylogging, screenshots, PowerShell execution), use of cloud storage services for command-and-control (Icedrive, Filen, previously pCloud/Koofr), reuse of XAgent code and rare obfuscation techniques linking these implants to APT28’s custom arsenal.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.