Threat Intelligence

Extended APT28 cyberespionage campaign against Ukraine discovered

Spyware and ransomware concept with digital glitch effect, spooky hooded hacker with magnifying glass stealing online identity nad hacking personal web accounts.

Attacks with the Beardshell and Covenant malware have been launched by Russian state-sponsored advanced persistent threat operation APT28 against Ukrainian military personnel as part of a cyberespionage campaign that has been underway for nearly two years, Security Affairs reports.

APT28 also known as Fancy Bear, Sednit, BlueDelta, Sofacy Group, and Pawn Storm has used the paired implants alongside the SlimAgent keylogger, which is believed to have evolved from XAgent tool previously leveraged by the hacking operation, to compromise the Ukrainian military since April 2024, according to an ESET report. Further analysis showed BeardShell's inclusion of the opaque predicate obfuscation technique, which is shared with APT28's XTunnel tool, as well as the significant alterations in Covenant to power long-term cyberespionage.

"The sophistication of BeardShell and the extensive modifications made to Covenant demonstrate that Sednit's developers remain fully capable of producing advanced custom implants. Furthermore, the shared code and techniques linking these tools to their 2010-era predecessors strongly suggest continuity within the development team," said researchers.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds