#BeardShell
#ESETresearch has analyzed the resurgence of Sednit – one of the most long‑running Russia‑aligned APT groups – now using a modern toolkit built around paired implants, BeardShell and Covenant, each using a different cloud provider for resilience. www.welivesecurity.com/en/eset-rese... 1/5
Sednit reloaded: Back in the trenches
ESET researchers document how the Sednit APT group has reemerged with a modern toolkit centered on two paired implants – BeardShell and Covenant.
www.welivesecurity.com
March 10, 2026 at 2:28 PM
APT28 With Weaponized Office Documents Delivers BeardShell and Covenant Modules
APT28 With Weaponized Office Documents Delivers BeardShell and Covenant Modules
cybersecuritynews.com
October 17, 2025 at 12:38 PM
The Russian state-sponsored threat group APT28 is using Signal chats to target government targets in Ukraine with two previously undocumented malware families named BeardShell and SlimAgent.
APT28 hackers use Signal chats to launch new malware attacks on Ukraine
The Russian state-sponsored threat group APT28 is using Signal chats to target government targets in Ukraine with two previously undocumented malware families named BeardShell and SlimAgent.
www.bleepingcomputer.com
June 23, 2025 at 10:15 PM
Wie gefährlich Mobilfunk #Messenger, wie #Signal sind zeigt leider mal wieder die #Ukraine

Die russischen Hacker von #ATP28 verschicken inflitrierte Dateien & missbrauchen die Geräteverknüpfungsfunktion der #SignalApp.

#Threema kostet dort fast nichts!

www.bleepingcomputer.com/news/securit...
APT28 hackers use Signal chats to launch new malware attacks on Ukraine
The Russian state-sponsored threat group APT28 is using Signal chats to target government targets in Ukraine with two previously undocumented malware families named BeardShell and SlimAgent.
www.bleepingcomputer.com
June 25, 2025 at 3:08 PM
Great work by Sekoia uncovering new #BlueDelta #APT28 #Sofacy #FancyBear #ForestBlizzard #TAG110 malware samples. Linked to CERT-UA’s BeardShell & Covenant frameworks + revealed fresh weaponized docs & subtle TTPs. Activity ties to Russia-nexus ops incl. Double-Tap. blog.sekoia.io/apt28-operat...
APT28 Operation Phantom Net Voxel
APT28 Operation Phantom Net Voxel: weaponized Office lures, COM-hijack DLL, PNG stego to Covenant Grunt via Koofr, BeardShell on icedrive.
blog.sekoia.io
September 16, 2025 at 9:24 AM
APT28 Uses Signal Chat to Deploy BEARDSHELL Malware and COVENANT in Ukraine

The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new cyber attack campaign by the Russia-linked APT28 (aka UAC-0001) threat actors using Signal chat messages to deliver two new m…

#hackernews #news
APT28 Uses Signal Chat to Deploy BEARDSHELL Malware and COVENANT in Ukraine
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new cyber attack campaign by the Russia-linked APT28 (aka UAC-0001) threat actors using Signal chat messages to deliver two new malware families dubbed BEARDSHELL and COVENANT. BEARDSHELL, per CERT-UA, is written in C++ and offers the ability to download and execute PowerShell scripts, as well as upload the results of the
thehackernews.com
June 25, 2025 at 6:50 AM
Sednit, aka APT28/Fancy Bear 🐻🇷🇺, is deploying two new potent hacking tools, Beardshell and Covenant, primarily targeting Ukrainian military personnel. My ESET colleagues analyze this GRU-homemade toolset in a new blogpost.
www.welivesecurity.com/en/eset-rese...
Sednit reloaded: Back in the trenches
ESET researchers document how the Sednit APT group has reemerged with a modern toolkit centered on two paired implants – BeardShell and Covenant.
www.welivesecurity.com
March 10, 2026 at 10:50 PM
APT28 Uses BEARDSHELL and COVENANT Malware to Spy on Ukrainian Military
APT28 Uses BEARDSHELL and COVENANT Malware to Spy on Ukrainian Military
thehackernews.com
March 10, 2026 at 12:24 PM
Sednit also deployed BeardShell, an implant that executes PowerShell commands via a legitimate cloud service and uses a distinctive obfuscation technique also found in Xtunnel, Sednit’s network pivoting tool from the 2010s. 3/5
March 10, 2026 at 2:28 PM
Across 2025–2026, Sednit paired BeardShell with Covenant, the final block of its modern toolkit – a heavily reworked open-source implant built for long‑term espionage with a new protocol riding on another legitimate cloud provider. 4/5
March 10, 2026 at 2:28 PM
APT28 hackers use Signal chats to launch new malware attacks on Ukraine🔥

The Russian state-sponsored threat group APT28 is using #Signal chats to target government targets in #Ukraine with two undocumented malware families named #BeardShell and #SlimAgent🕵️‍♂️

www.bleepingcomputer.com/news/securit...
APT28 hackers use Signal chats to launch new malware attacks on Ukraine
The Russian state-sponsored threat group APT28 is using Signal chats to target government targets in Ukraine with two previously undocumented malware families named BeardShell and SlimAgent.
www.bleepingcomputer.com
June 24, 2025 at 8:16 AM
🇷🇺 🇺🇦 A notorious Russian military cyber espionage hacking group has been refining its malware to conduct long-term surveillance of targets in #Ukraine and beyond.

www.welivesecurity.com/en/eset-rese...

#Russia #cybersecurity
Sednit reloaded: Back in the trenches
ESET researchers document how the Sednit APT group has reemerged with a modern toolkit centered on two paired implants – BeardShell and Covenant.
www.welivesecurity.com
March 10, 2026 at 12:08 PM
Detailed analysis of Sednit’s modern toolkits is available at www.welivesecurity.com/en/eset-rese... 5/5
Sednit reloaded: Back in the trenches
ESET researchers document how the Sednit APT group has reemerged with a modern toolkit centered on two paired implants – BeardShell and Covenant.
www.welivesecurity.com
March 10, 2026 at 2:28 PM
I did a blurb about APT44 the other day, so I shouldn't ignore what APT28 aka Fancy Bear have been up to recently. New-ish report from Sekoia on what APT28 have been doing this year. New info regarding 2 new malware samples, connecting them to other attacks not previously attributed to APT28.
APT28 Operation Phantom Net Voxel
APT28 Operation Phantom Net Voxel: weaponized Office lures, COM-hijack DLL, PNG stego to Covenant Grunt via Koofr, BeardShell on icedrive.
blog.sekoia.io
November 4, 2025 at 7:36 PM
CERT-UA sounds alarm on a new wave of ongoing UAC-0001 (APT28) attacks against Ukrainian state bodies using the BEARDSHELL framework and COVENANT backdoor. Detect malicious activity with curated Sigma rules available in the SOC Prime Platform.
buff.ly/vpPKAhJ
#cybersecurity #detectionengineering
June 24, 2025 at 11:59 AM
Russian hacking group APT28 deploys BEARDSHELL and COVENANT malware to spy on Ukrainian military. #CyberSecurity #APT28 #Ukraine #Malware Link: thedailytechfeed.com/apt28-deploy...
March 11, 2026 at 6:38 PM
#APT28 Weaponizes MS Office Flaw to #Spy on #NATO & #Military

#Russia state-sponsored group #FancyBear has launched a sophisticated espionage campaign, striking #Europe #military & #government through a major security vulnerability in #Microsoft #Office.

securityonline.info/apt28-weapon...
APT28 Weaponizes Office Flaw to Spy on NATO & Military
APT28 (Fancy Bear) weaponized CVE-2026-21509 in 24 hours to target NATO. New "BeardShell" and "NotDoor" malware steals emails. Patch Office now.
securityonline.info
February 9, 2026 at 9:00 AM
📃 APT28 distributed weaponised Office documents masquerading as Ukrainian military admin forms to harvest cyber-military intelligence.

🕷️ Attackers deploy a custom backdoor dubbed BeardShell using a modified Covenant Grunt stager.
September 16, 2025 at 12:59 PM
The Sekoia.io Threat Detection and Response team links two early 2025 APT28 samples to the CERT UA BeardShell and Covenant publication on 21 June 2025 and reports additional weaponized Office documents and previously undocumented techniques. blog.sekoia.io/apt28-operat...
September 17, 2025 at 8:25 AM
Sednit reloaded: Back in the trenches
The resurgence of one of Russia’s most notorious APT groups
www.welivesecurity.com/en/eset-rese...
Sednit reloaded: Back in the trenches
ESET researchers document how the Sednit APT group has reemerged with a modern toolkit centered on two paired implants – BeardShell and Covenant.
www.welivesecurity.com
March 10, 2026 at 6:49 PM
APT28 hackers use Signal chats to launch new malware attacks on Ukraine
APT28 hackers use Signal chats to launch new malware attacks on Ukraine
The Russian state-sponsored threat group APT28 is using Signal chats to target government targets in Ukraine with two previously undocumented malware families named BeardShell and SlimAgent.
www.bleepingcomputer.com
June 23, 2025 at 10:50 PM