Malware & Threats

Russian APT Hits Ukrainian Government With New Malware via Signal

Russia-linked APT28 deployed new malware against Ukrainian government targets through malicious documents sent via Signal chats.

Russia attack on Ukraine

A Russian state-sponsored hacking group has infected Ukrainian government entities with new malware after sending malicious documents over Signal, the Computer Emergency Response Team of Ukraine (CERT-UA) says.

An investigation into a March-April 2024 intrusion at a government organization uncovered two new malware families, dubbed BeardShell and SlimAgent, but the infection vector remained a mystery.

Analysis of a May 2025 attack that compromised a gov.ua email account uncovered the use of BeardShell and a component of the Covenant framework, as well as the initial intrusion avenue, namely Signal.

Specifically, an unnamed target within the government organization received through a Signal chat an Office document containing macro code that led to the execution of the malware.

The attackers, CERT-UA says, had good knowledge of the targeted individual and of the organization.

Written in C++, BeardShell is a backdoor that supports the download, decryption, and execution of PowerShell scripts. It uses the Icedrive service API for management, CERT-UA says.

Advertisement. Scroll to continue reading.

The backdoor relies on a COM-hijacking method within the Windows registry to persist even after system reboots.

SlimAgent, which is written in C++ as well, can take screenshots on the infected system, encrypt them, and save them locally, likely for future exfiltration. It relies on a Windows API for screenshot capturing and uses AES and RSA to encrypt the images.

Their use suggests that the attack was intended for establishing a long-term foothold on the compromised systems, for intelligence gathering.

The Covenant framework was likely used to download additional payloads that ultimately led to the deployment of the BeardShell backdoor.

CERT-UA blames the intrusions on APT28, also known as Fancy Bear, Forest Blizzard, Pawn Storm, Sednit, and Sofacy Group, which has been connected by security researchers to Russia’s Main Intelligence Directorate of the General Staff (GRU).

APT28 has been systematically targeting Western logistics and technology companies that deliver weapons, aid, and other supplies to Ukraine, cybersecurity agencies in the US and other allied countries said last month.

Related: Russian APT Exploiting Mail Servers Against Government, Defense Organizations

Related: Microsoft, CrowdStrike Lead Effort to Map Threat Actor Names

Related: US Government Urges Cleanup of Routers Infected by Russia’s APT28

Related Content

Malware & Threats

The malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems.

Artificial Intelligence

SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot.

Malware & Threats

Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop.

Malware & Threats

The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533.

Malware & Threats

The new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency. 

Endpoint Security

Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint security products.

Cybercrime

The suspects and their companies were previously sanctioned by the United States and its allies.

Government

Multiple state-sponsored APTs are compromising poorly secured devices across critical infrastructure sector networks.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version