[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fLy9KwKsVHcWPHpnyhWPf9vlj7RZYFigyqt1VJhYN4TI":3},{"article":4,"iocs":36,"watch_terms":46},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":10,"url":11,"image_url":12,"published_at":13,"ingested_at":14,"relevance_score":10,"entities":15,"category_id":16,"category":17,"article_tags":20},"5f7e0137-ab0a-4a68-9ed9-0d0107320e88","APT28 Uses BEARDSHELL and COVENANT Malware to Spy on Ukrainian Military","apt28-uses-beardshell-and-covenant-malware-to-spy-on-ukrainian-military","The Russian state-sponsored hacking group tracked as APT28 has been observed using a pair of implants dubbed BEARDSHELL and COVENANT to facilitate long‑term surveillance of Ukrainian military personnel. The two malware families have been put to use since April 2024, ESET said in a new report shared with The Hacker News. APT28, also tracked as Blue Athena, BlueDelta, Fancy Bear, Fighting Ursa,","Russian state-sponsored APT28 has been conducting surveillance operations against Ukrainian military personnel using two malware implants named BEARDSHELL and COVENANT since April 2024. The campaign represents ongoing cyber espionage efforts by the threat actor against Ukrainian defense targets. ESET researchers documented the malware families and their operational deployment in detailed threat intelligence reporting.",null,"https:\u002F\u002Fthehackernews.com\u002F2026\u002F03\u002Fapt28-uses-beardshell-and-covenant.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEg-By3tHSMSOxuaRiOmtalZ7sltfDCZ-ZfA-SYEQ6RVae4iQoVJVeUZU380kIIgrdAnFkX516x6OdctG7NCgL3zNSSENMqgc1iNcSC48aIJ3sx7eAK1-5rGqPu00i5rfPpvxOQ9I9R-v1fPL-i_i0kreyvQ3a0WuneswNUZgnhaTKq6fFu3me-1TopHYcl1\u002Fs1600\u002FUkrainian-malware.jpg","2026-03-10T10:55:00+00:00","2026-03-14T09:41:13.354083+00:00",[],"6cbdd207-aaa1-4176-9534-e156b125e917",{"id":16,"icon":10,"name":18,"slug":19},"Nation-state","nation-state",[21,26,31],{"category":22},{"id":23,"icon":10,"name":24,"slug":25},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":27},{"id":28,"icon":10,"name":29,"slug":30},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",{"category":32},{"id":33,"icon":10,"name":34,"slug":35},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[37,40,42],{"type":25,"value":38,"context":39},"BEARDSHELL","Implant used by APT28 for surveillance of Ukrainian military",{"type":25,"value":41,"context":39},"COVENANT",{"type":43,"value":44,"context":45},"mitre_attack","APT28","Russian state-sponsored threat actor, also tracked as Blue Athena, BlueDelta, Fancy Bear, Fighting Ursa",[]]