Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Russian APT Hits Ukrainian Government With New Malware via Signal

Russia-linked APT28 deployed new malware against Ukrainian government targets through malicious documents sent via Signal chats.

Russia attack on Ukraine

A Russian state-sponsored hacking group has infected Ukrainian government entities with new malware after sending malicious documents over Signal, the Computer Emergency Response Team of Ukraine (CERT-UA) says.

An investigation into a March-April 2024 intrusion at a government organization uncovered two new malware families, dubbed BeardShell and SlimAgent, but the infection vector remained a mystery.

Analysis of a May 2025 attack that compromised a gov.ua email account uncovered the use of BeardShell and a component of the Covenant framework, as well as the initial intrusion avenue, namely Signal.

Specifically, an unnamed target within the government organization received through a Signal chat an Office document containing macro code that led to the execution of the malware.

The attackers, CERT-UA says, had good knowledge of the targeted individual and of the organization.

Written in C++, BeardShell is a backdoor that supports the download, decryption, and execution of PowerShell scripts. It uses the Icedrive service API for management, CERT-UA says.

Advertisement. Scroll to continue reading.

The backdoor relies on a COM-hijacking method within the Windows registry to persist even after system reboots.

SlimAgent, which is written in C++ as well, can take screenshots on the infected system, encrypt them, and save them locally, likely for future exfiltration. It relies on a Windows API for screenshot capturing and uses AES and RSA to encrypt the images.

Their use suggests that the attack was intended for establishing a long-term foothold on the compromised systems, for intelligence gathering.

The Covenant framework was likely used to download additional payloads that ultimately led to the deployment of the BeardShell backdoor.

CERT-UA blames the intrusions on APT28, also known as Fancy Bear, Forest Blizzard, Pawn Storm, Sednit, and Sofacy Group, which has been connected by security researchers to Russia’s Main Intelligence Directorate of the General Staff (GRU).

APT28 has been systematically targeting Western logistics and technology companies that deliver weapons, aid, and other supplies to Ukraine, cybersecurity agencies in the US and other allied countries said last month.

Related: Russian APT Exploiting Mail Servers Against Government, Defense Organizations

Related: Microsoft, CrowdStrike Lead Effort to Map Threat Actor Names

Related: US Government Urges Cleanup of Routers Infected by Russia’s APT28

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Alex Levinson has been named Executive Director at the National Collegiate Cyber Defense Competition.

Hack The Box has appointed Konstantinos Dolkas as CTO and has promoted Christine Bartlett to CMO.

The Department of Energy has appointed Andrew McClure as Director of the Office of Cybersecurity, Energy Security, and Emergency Response (CESER).

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.