Back to Feed
Nation-stateMar 10, 2026

APT28 Uses BEARDSHELL and COVENANT Malware to Spy on Ukrainian Military

Russian state-sponsored APT28 has been conducting surveillance operations against Ukrainian military personnel using two malware implants named BEARDSHELL and COVENANT since April 2024. The campaign represents ongoing cyber espionage efforts by the threat actor against Ukrainian defense targets. ESET researchers documented the malware families and their operational deployment in detailed threat intelligence reporting.

Summary

Russian state-sponsored APT28 has been conducting surveillance operations against Ukrainian military personnel using two malware implants named BEARDSHELL and COVENANT since April 2024. The campaign represents ongoing cyber espionage efforts by the threat actor against Ukrainian defense targets. ESET researchers documented the malware families and their operational deployment in detailed threat intelligence reporting.

Indicators of Compromise

  • malware — BEARDSHELL
  • malware — COVENANT
  • mitre_attack — APT28