#SlimAgent
The Russian state-sponsored threat group APT28 is using Signal chats to target government targets in Ukraine with two previously undocumented malware families named BeardShell and SlimAgent.
APT28 hackers use Signal chats to launch new malware attacks on Ukraine
The Russian state-sponsored threat group APT28 is using Signal chats to target government targets in Ukraine with two previously undocumented malware families named BeardShell and SlimAgent.
www.bleepingcomputer.com
June 23, 2025 at 10:15 PM
ESET researchers tied Sednit’s advanced implant team reboot to a 2024 case in Ukraine, where SlimAgent emerged – a keylogger built on the codebase of the infamous Xagent, Sednit’s flagship 2010-era backdoor. 2/5
March 10, 2026 at 2:28 PM
Wie gefährlich Mobilfunk #Messenger, wie #Signal sind zeigt leider mal wieder die #Ukraine

Die russischen Hacker von #ATP28 verschicken inflitrierte Dateien & missbrauchen die Geräteverknüpfungsfunktion der #SignalApp.

#Threema kostet dort fast nichts!

www.bleepingcomputer.com/news/securit...
APT28 hackers use Signal chats to launch new malware attacks on Ukraine
The Russian state-sponsored threat group APT28 is using Signal chats to target government targets in Ukraine with two previously undocumented malware families named BeardShell and SlimAgent.
www.bleepingcomputer.com
June 25, 2025 at 3:08 PM
APT28 hackers use Signal chats to launch new malware attacks on Ukraine🔥

The Russian state-sponsored threat group APT28 is using #Signal chats to target government targets in #Ukraine with two undocumented malware families named #BeardShell and #SlimAgent🕵️‍♂️

www.bleepingcomputer.com/news/securit...
APT28 hackers use Signal chats to launch new malware attacks on Ukraine
The Russian state-sponsored threat group APT28 is using Signal chats to target government targets in Ukraine with two previously undocumented malware families named BeardShell and SlimAgent.
www.bleepingcomputer.com
June 24, 2025 at 8:16 AM
APT28 hackers use Signal chats to launch new malware attacks on Ukraine
APT28 hackers use Signal chats to launch new malware attacks on Ukraine
The Russian state-sponsored threat group APT28 is using Signal chats to target government targets in Ukraine with two previously undocumented malware families named BeardShell and SlimAgent.
www.bleepingcomputer.com
June 23, 2025 at 10:50 PM
APT28’s New Malware Campaign: How Signal is Being Weaponized Against Ukraine

Introduction The Russian state-sponsored hacking group APT28 (also known as Fancy Bear) has been observed leveraging Signal, the encrypted messaging platform, to distribute two new malware strains—BeardShell and…
APT28’s New Malware Campaign: How Signal is Being Weaponized Against Ukraine
Introduction The Russian state-sponsored hacking group APT28 (also known as Fancy Bear) has been observed leveraging Signal, the encrypted messaging platform, to distribute two new malware strains—BeardShell and SlimAgent—targeting Ukrainian government entities. While this is not a vulnerability in Signal itself, the platform is being exploited as a phishing vector due to its widespread adoption among high-profile targets. This article explores the technical aspects of these attacks, detection methods, and mitigation strategies.
undercodetesting.com
June 24, 2025 at 4:45 AM
Notícia da BleepingComputer

"APT28 hackers use Signal chats to launch new malware attacks on Ukraine" #bolhasec
APT28 hackers use Signal chats to launch new malware attacks on Ukraine
The Russian state-sponsored threat group APT28 is using Signal chats to target government targets in Ukraine with two previously undocumented malware families named BeardShell and SlimAgent.
www.bleepingcomputer.com
September 14, 2025 at 8:30 PM
ウクライナのサイバーセキュリティ当局によると、ロシア軍事情報機関関連のハッカーグループAPT28が、Signalアプリを悪用し、新たなマルウェアBeardShellとSlimAgentでウクライナ政府機関を攻撃している。 therecord.media/ukraine-new-...
Social engineering and Signal chats led to new Russian malware attacks, Ukraine says
Ukraine's cybersecurity agency said the Russian group tracked as APT28, Fancy Bear or Forest Blizzard was responsible for targeting new malware strains at government officials.
therecord.media
June 24, 2025 at 2:00 PM
TL;DR

* ESET-SlimAgent and Xagent cyber threats detected in Ukraine and Russia, targeting critical infrastructure with malware
* Iran-linked APT28 deploys BeardShell and Covenant implants for long-term espionage against Ukrainian military targets
* AI-powered phishing and deepfakes surge as […]
120 Ukraine Gov Boxes Hacked 8 Yrs—Europe’s 2008 Servers Next Target
### TL;DR * ESET-SlimAgent and Xagent cyber threats detected in Ukraine and Russia, targeting critical infrastructure with malware * Iran-linked APT28 deploys BeardShell and Covenant implants for long-term espionage against Ukrainian military targets * AI-powered phishing and deepfakes surge as attackers reduce cost of social engineering by over 95%, per 2026 threat report * * * ## 🪓 120 Ukraine Gov Endpoints Hijacked: 8-Year GRU SlimAgent Grid Siege > 120+ Ukrainian gov boxes pwned for 8 yrs by GRU’s SlimAgent—same malware that siphons your keystrokes while you patch PowerPoint 🪓 68 % code recycle rate=green hacking for Putin. 2 % power dip=just enough to fry a grid. Europe, you’re next—still running Server 2008? Ukraine’s grid keeps hiccupping because eight-year-old malware is still squatting on government PCs like a drunk uncle who “just needs a minute.” SlimAgent/XAgent, the GRU’s favorite house-guest, has lived in 120+ Ukrainian ministry boxes since 2018 and is now encrypting its gossip with ChaCha20—because even spies hate ISP snooping. ### How it works (spoiler: duct-tape & PowerShell) * BeardShell, a .NET stowaway, rides in on a poisoned Word doc (CVE-2026-21509). * Once inside, it phones Icedrive—yes, the same freemium cloud you use for cat pics—exfiltrating screenshots, passwords, and SCADA schematics. * Covenant’s 90-in-one hacker Swiss-army-knife then impersonates admins, dumps credentials, and schedules reboot-proof tasks. * Average stay: 180 days, double the old single-implant record. ### Impacts in human-sized bites **Lights** : ≤2 % of Ukraine’s regional load shed last month after crooks re-configured substations. **Data** : 30+ industrial controllers now broadcast plant floor blueprints to Moscow. **Cash** : every re-clean costs ~$25 k per endpoint; 120 endpoints → $3 M babysitting bill. **Trust** : credential leaks trigger 3,200 spear-phish clones a day—your inbox is next. ### Short-to-long-term forecast (mark your calendar) * **Spring 2026** : BeardShell 2.0 skips files, lives only in RAM—hello “file-less” hell. * **Late-2026** : C2 scatters to Google Drive, Azure Blob, whatever’s cheapest—sink-hole-proof. * **2027** : AI obfuscation expected to raise detection workload 30 %—SOC analysts, buy espresso futures now. ### Cheap fixes that actually fit the budget 1. Patch Office today; tomorrow is too late. 2. Block Icedrive at the firewall—users can survive without 50 GB of free crud. 3. Flip PowerShell to ConstrainedLanguage—cripples BeardShell, doesn’t cost a dime. 4. Retire Server 2008 like it’s a mullet: nostalgic, but lethal. Bottom line: If legacy boxes remain the path of least resistance, Ukraine’s electrons—and everyone else’s—will keep dancing to a Russian playlist. Patch, block, retire, repeat—or stock candles. * * * ## 💥 200 Ukrainian Military PCs Drained: 12 GB/Month to Icedrive in Iran-Backed APT28 Heist > 200+ Ukrainian frontline laptops pwned—12 GB/month siphoned to Icedrive like a leaky bucket in a firefight! 💥 Tehran’s ‘Bear’ recycles 2010 malware & a fresh Office 0-day to keep the taps open. Your tax € fund the bandwidth they hide in. Soldiers—how many more blue-screens before we unplug the cloud? Iran-linked APT28 rebooted its malware sweat-shop last April and has since parked two digital parasites—BeardShell and Covenant—inside more than 200 Ukrainian military endpoints. The haul: 12 GB of fresh files **per month, per implant** , all quietly uploaded to Icedrive accounts that look just like any other corporate backup. ### How the sneaky duo works * **BeardShell** : a PowerShell blob that lives inside .NET, chats with Icedrive (no public API, so they rewrote the client), and hides its chatter behind Xtunnel-style obfuscation. * **Covenant** : an open-source post-exploitation Swiss-army knife the group turbo-charged with 90+ tasks, deterministic IDs, and multi-cloud fallback (pCloud, Koofr, Filen). * Entry ticket: CVE-2026-21509, a remote-code hole in Office docs that’s been exploited since January via spear-phish. ### Impacts so far * **Operational secrecy** : every keystroke, screenshot and clipped password is HTML-logged → real-time battlefield intel for Tehran. * **Bandwidth camouflage** : exfil rides the same TLS tunnels your marketing team uses for cloud storage → SOC barely blinks. * **Credential bloodletting** : harvested logins already enable lateral jumps into logistics and shared EU-NATO clouds. ### Where this is heading * **Q2-Q3 2026** : expect JIT-compiled PowerShell and OneDrive-for-Business pivot → harder to fingerprint, easier to justify as “normal” traffic. * **2027** : modular “C2Bridge” to auto-hop across ten-plus clouds; supply-chain targeting to mess with troop resupply. ### Fix-it list (no corporate PowerPoint required) 1. Patch CVE-2026-21509 **today** ; disable Office macros if you still allow them. 2. Flag any outbound TLS to Icedrive/pCloud/Koofr/Filen; 12 GB spikes should scream, not whisper. 3. Drop updated YARA rules for BeardShell’s PowerShell sigs and Covenant’s deterministic IDs—GitHub has drafts, use them. 4. Rotate creds weekly and slam MFA on every account that can read military email. Cyber-espionage used to mean bespoke zero-days and Bond-villan server farms. APT28 proves recycled open-source tools plus one fresh Office bug are enough to gut a war plan. If your network touches Ukrainian defense data, assume the parasites are already nesting—patch, hunt, kick them out before the next 12 GB shipment clears the digital border. * * * ## 💸 $30 B AI Scam Tsunami: 95 % Cost Drop Fuels Global Deepfake Plague > 95 % cheaper, 100 % nastier: AI now pumps phishing & deepfakes for the price of a pizza 🍕—and your CFO’s still clicking ‘pay’! $25.6 M gone in one Zoom, 47 % of India’s phones already duped. While regulators nap, $30 B vanishes. Ready to mute the machines, or keep footing the bill? Last Thursday Arup wired $25.6 million because a deepfake CFO said “jump.” Cost to the crooks? Thirty bucks for a monthly AI-phishing kit and three seconds of scraped audio. That 95 % price drop turns every bored script-kiddie into a con-artist with a Hollywood budget. ### How does this work Voice cloning needs < 3 s of your “hello?” from TikTok. Large-language models spin 1 265 % more phishing mails than last year, each tuned with breached HR data. Cisco’s red-teamers prove 60 % of “safety” guardrails fold after five chat turns—like a bouncer who lets you in if you ask nicely five times. ### Impacts * **Wallet** : synthetic-ID fraud already siphoned ≥ $30 B since 2023—equal to the GDP of Bolivia. * **Trust** : 47 % of Indian mobile users now flinch at every unknown call; Europe clocks +311 % fake-ID loans. * **Boardroom** : 94 % of login attempts are bots, so your multi-factor token is just another souvenir. ### Institutional response (spoiler: still buffering) Enterprises lecture staff with 2019-era slide decks that cover < 30 % of today’s scam surface. EU watermark rules? Pending until 2027—light-years in AI dog-years. Meanwhile open-source repos drop 200 new malicious models a week, priced at a latte. ### Timelines to watch * **Q3-2026** : voice-scam volume +30 %; detection false-positives still 12 %—your IT helpdesk drowns. * **2028** : attacker cost plateaus at < 5 % of 2022 levels; social-engineering becomes the default, not the exception. * **2030** : only media with cryptographic birth-certificates gets through—email without it hits the trash like spam from a prince. ### The takeaway When the cost of deception drops below a Netflix subscription, reputation becomes the only currency left. Start watermarking your Zoom recordings, bind logins to how you type—not what you type—and treat every unexpected “hi, it’s me” like a $25 million question. * * * ### In Other News * Hacker leaks 12GB of personal data from Cal AI, affecting 3 million users after exploiting MyFitnessPal breach * Mullvad’s GotaTUN WireGuard implementation passes audit with two low-severity padding deviations fixed * Law enforcement dismantles Tycoon 2FA phishing-as-a-service platform, disrupting 96,000+ phishing victims since 2023 * Prompt injection tops OWASP’s LLM Top 10 as attackers bypass safety filters to extract data and hijack AI agents
espresso.cafecito.tech
March 11, 2026 at 2:02 PM
Russian APT28 Targets Ukraine Using Signal to Deliver New Malware Families #cyberattack #CyberAttacks #cybersecuritynews
Russian APT28 Targets Ukraine Using Signal to Deliver New Malware Families
 The Russian state-sponsored threat group APT28, also known as UAC-0001, has been linked to a fresh wave of cyberattacks against Ukrainian government targets, using Signal messenger chats to distribute two previously undocumented malware strains—BeardShell and SlimAgent.  While the Signal platform itself remains uncompromised, its rising adoption among government personnel has made it a popular delivery vector for phishing attacks. Ukraine’s Computer Emergency Response Team (CERT-UA) initially discovered these attacks in March 2024, though critical infection vector details only surfaced after ESET notified the agency in May 2025 of unauthorised access to a “gov.ua” email account.  Investigations revealed that APT28 used Signal to send a macro-laced Microsoft Word document titled "Акт.doc." Once opened, it initiates a macro that drops two payloads—a malicious DLL file (“ctec.dll”) and a disguised PNG file (“windows.png”)—while modifying the Windows Registry to enable persistence via COM-hijacking.  These payloads execute a memory-resident malware framework named Covenant, which subsequently deploys BeardShell. BeardShell, written in C++, is capable of downloading and executing encrypted PowerShell scripts, with execution results exfiltrated via the Icedrive API. The malware maintains stealth by encrypting communications using the ChaCha20-Poly1305 algorithm.  Alongside BeardShell, CERT-UA identified another tool dubbed SlimAgent. This lightweight screenshot grabber captures images using multiple Windows API calls, then encrypts them with a combination of AES and RSA before local storage. These are presumed to be extracted later by an auxiliary tool.  APT28’s involvement was further corroborated through their exploitation of vulnerabilities in Roundcube and other webmail software, using phishing emails mimicking Ukrainian news publications to exploit flaws like CVE-2020-35730, CVE-2021-44026, and CVE-2020-12641. These emails injected malicious JavaScript files—q.js, e.js, and c.js—to hijack inboxes, redirect emails, and extract credentials from over 40 Ukrainian entities. CERT-UA recommends organisations monitor traffic linked to suspicious domains such as “app.koofr.net” and “api.icedrive.net” to detect any signs of compromise.
dlvr.it
July 1, 2025 at 1:42 PM
UAC-0001 Hackers Attacking ICS Devices Running Windows Systems as a Server
UAC-0001 Hackers Attacking ICS Devices Running Windows Systems as a Server
APT28 hit Ukrainian govt ICS servers with BEARDSHELL & SLIMAGENT malware in a major March–April 2024 cyberattack on critical systems.
cybersecuritynews.com
June 23, 2025 at 5:05 PM
APT28 hackers use Signal chats to launch new malware attacks on Ukraine

The Russian state-sponsored threat group APT28 is using Signal chats to target government targets in Ukraine with two previously undocumented malware families named BeardShell and SlimAgent. To be clear, this is not a security…
APT28 hackers use Signal chats to launch new malware attacks on Ukraine
The Russian state-sponsored threat group APT28 is using Signal chats to target government targets in Ukraine with two previously undocumented malware families named BeardShell and SlimAgent. To be clear, this is not a security issue in Signal. Instead, threat actors are more commonly utilizing the messaging platform as part of their phishing attacks due to its increased usage by governments worldwide.
nexttech-news.com
June 24, 2025 at 5:01 AM
Russia-linked APT28 use Signal chats to target Ukraine official with malware

Russia-linked group APT28 uses Signal chats as an attack vector to phish Ukrainian officials with new malware strains. Russia-linked cyberespionage group APT28 is targeting Ukrainian government official…

#hackernews #news
Russia-linked APT28 use Signal chats to target Ukraine official with malware
Russia-linked group APT28 uses Signal chats as an attack vector to phish Ukrainian officials with new malware strains. Russia-linked cyberespionage group APT28 is targeting Ukrainian government officials using Signal chats to deliver two new types of malware, tracked as BeardShell and SlimAgent. While Signal itself remains secure, attackers are exploiting its growing popularity in official […]
securityaffairs.com
June 25, 2025 at 10:48 AM
APT28 hackers use Signal chats to launch new malware attacks on Ukraine

The Russian state-sponsored threat group APT28 is using Signal chats to target government targets in Ukraine with two previously undocumented malware families named BeardShell and SlimAgent. [...]

#hackernews #news
APT28 hackers use Signal chats to launch new malware attacks on Ukraine
The Russian state-sponsored threat group APT28 is using Signal chats to target government targets in Ukraine with two previously undocumented malware families named BeardShell and SlimAgent. [...]
www.bleepingcomputer.com
June 24, 2025 at 10:52 PM
APT28 hackers use Signal chats to launch new malware attacks on Ukraine

#news #worldnews
APT28 hackers use Signal chats to launch new malware attacks on Ukraine
The Russian state-sponsored threat group APT28 is using Signal chats to target government targets in Ukraine with two previously undocumented malware families named BeardShell and SlimAgent.
www.bleepingcomputer.com
June 24, 2025 at 6:20 AM
ロシア関連のAPT28がSignalチャットを利用してウクライナ政府関係者をマルウェアで攻撃

ロシアと関係のあるサイバースパイ集団APT28は、Signalチャットを利用してウクライナ政府関係者を標的とし、BeardShellとSlimAgentと呼ばれる2種類の新しいマルウェアを拡散させています。Signal自体は依然として安全ですが、攻撃者は公式コミュニケーションにおけるSignalの普及率の高まりを悪用し、フィッシング攻撃の信憑性を高めています。

2024年3月から4月にかけて、ウクライナの中央執行機関の情報通信システム内でのインシデント対応中に、ウクライナのコンピューターおよ...
Russia-linked APT28 use Signal chats to target Ukraine official with malware
Russia-linked group APT28 uses Signal chats as an attack vector to phish Ukrainian officials with new malware strains.
securityaffairs.com
June 29, 2025 at 8:51 AM
ソーシャルエンジニアリングとシグナルチャットがロシアの新たなマルウェア攻撃につながったとウクライナが発表

ウクライナのサイバーセキュリティ当局によると、ロシア軍情報部と関係のあるハッキンググループが、シグナルメッセージングアプリを通じて配信された新たに発見されたマルウェアでウクライナ政府機関を標的にしている。

最新の攻撃キャンペーンで使用された2種類のマルウェア(BeardShellとSlimAgent)は、ウクライナのコンピュータ緊急対応チーム(CERT-UA)によって特定されました。BeardShellはPowerShellスクリプトを実行できるバックドアとして機能し、SlimA...
Social engineering and Signal chats led to new Russian malware attacks, Ukraine says
Ukraine's cybersecurity agency said the Russian group tracked as APT28, Fancy Bear or Forest Blizzard was responsible for targeting new malware strains at government officials.
therecord.media
June 29, 2025 at 8:48 AM
ロシアのAPTは信号を介して新しいマルウェアでウクライナ政府を攻撃します

ウクライナのコンピュータ緊急対応チーム(CERT-UA)によると、ロシアの国家が後援するハッキンググループが、Signalを介して悪意のある文書を送信した後、ウクライナの政府機関に新しいマルウェアを感染させました。

2024年3月から4月にかけての政府機関への侵入の調査では、BeardShellとSlimAgentと呼ばれる2つの新しいマルウェアファミリーが明らかになりましたが、感染のベクトルは謎のままでした。
Russian APT Hits Ukrainian Government With New Malware via Signal
Russia-linked APT28 deployed new malware against Ukrainian government targets through malicious documents sent via Signal chats.
www.securityweek.com
June 26, 2025 at 9:01 PM
UAC-0001 ハッカーがWindowsベースのサーバーシステムを実行するICSデバイスを標的に

サイバーインシデントに対応する国家チームCERT-UAは、2024年3月から4月にかけて中央執行機関の情報通信システム(ICS)を標的とした高度なサイバー攻撃があったことを明らかにした。

対応策の実施中に、サーバーとして機能する Windows オペレーティング システムを実行する技術デバイスが、BEARDSHELL と SLIMAGENT という 2 つの悪意のあるソフトウェア ツールによって侵害されていることが判明しました。
UAC-0001 Hackers Target ICS Devices Running Windows-Based Server Systems
The national team for responding to cyber incidents, CERT-UA, has exposed a sophisticated cyberattack targeting the ICS.
gbhackers.com
June 24, 2025 at 1:35 PM
UAC-0001(APT28)によるBEARDSHELLとCOVENANTを使用した政府機関へのサイバー攻撃

2024年3月から4月にかけて、中央執行機関の情報通信システム(ICS)におけるサイバーインシデントへの対応中に、サイバーインシデント、サイバー攻撃、サイバー脅威に対応するための国家チームであるCERT-UAは、サーバーとして機能するWindowsオペレーティングシステムを実行する技術デバイスを特定しました。そのデバイス上で、サイバー脅威を実行するための2つのソフトウェアツール、つまりBEARDSHELLとSLIMAGENTが検出されました。
CERT-UA
Урядова команда реагування на комп’ютерні надзвичайні події України, яка функціонує в складі Державної служби спеціального зв’язку та захисту інформації України.
cert.gov.ua
June 24, 2025 at 1:35 PM
APT28ハッカーがSignalチャットを利用してウクライナに新たなマルウェア攻撃を開始

ロシア政府が支援する脅威グループ APT28 は、Signal チャットを使用して、これまで文書化されていない 2 つのマルウェア ファミリである BeardShell と SlimAgent でウクライナ政府を標的にしています。

念のため申し上げますが、これはSignalのセキュリティ問題ではありません。世界中の政府機関による利用が増えているため、脅威アクターはSignalをフィッシング攻撃の一環として悪用するケースが増えています。

この攻撃は2024年3月にウクライナのコンピューターおよび...
APT28 hackers use Signal chats to launch new malware attacks on Ukraine
The Russian state-sponsored threat group APT28 is using Signal chats to target government targets in Ukraine with two previously undocumented malware families named BeardShell and SlimAgent.
www.bleepingcomputer.com
June 24, 2025 at 1:35 PM