APT28 Uses BEARDSHELL and COVENANT Malware to Spy on Ukrainian Military
Russian state-sponsored APT28 has been conducting surveillance operations against Ukrainian military personnel using two malware implants named BEARDSHELL and COVENANT since April 2024. The campaign represents ongoing cyber espionage efforts by the threat actor against Ukrainian defense targets. ESET researchers documented the malware families and their operational deployment in detailed threat intelligence reporting.
Summary
Russian state-sponsored APT28 has been conducting surveillance operations against Ukrainian military personnel using two malware implants named BEARDSHELL and COVENANT since April 2024. The campaign represents ongoing cyber espionage efforts by the threat actor against Ukrainian defense targets. ESET researchers documented the malware families and their operational deployment in detailed threat intelligence reporting.
Indicators of Compromise
- malware — BEARDSHELL
- malware — COVENANT
- mitre_attack — APT28