HomeSecuritySignal: New APT28 attack distributes BeardShell and Covenant

Signal: New APT28 attack distributes BeardShell and Covenant

In late summer 2025, cybersecurity researchers uncovered a sophisticated spearphishing campaign, APT28, targeting Ukrainian military personnel via the Signal messaging platform. The operation, codenamed “Phantom Net Voxel,” begins with a malicious Office document sent through private conversations on Signal, pretending to be urgent administrative forms or compensation claims.

See also: Signal: Secure backups to save & restore conversations

APT28 Signal

Upon opening, the document's embedded macros drop a hidden DLL and a PNG file onto the victim's computer, starting a multi-layered infection chain that eventually installs both HTTP Grunt Stager and the custom BeardShell backdoor in C++.

Sekoia analysts identified the stealthy appearance of decoy documents, formatted with authentic Ukrainian military nomenclature, as a key element of the campaign’s success. The initial Document_Open macro verifies Windows versions and then uses the CreateProcessW API to register a malicious COM server under CLSID {2227A280-3AEA-1069-A2DE-08002B30309D}, ensuring that the DLL is loaded on every user logon.

If the registry key does not exist, the macro drops prnfldr.dll into the ProgramData directory and windows.png into AppData, hiding both files before calling regsvr32.exe /n /i to perform the DLL installation process.

Once loaded into explorer.exe, the second-stage DLL extracts a shellcode from the least significant bits of each PNG pixel. The embedded shellcode initializes the .NET Common Language Runtime (CLR) and injects a Covenant HTTP Grunt module, which communicates with the Koofr cloud to create directories named “Keeping” and “Transferring”. Hybrid encryption secures communications as file uploads and downloads provide a hidden command and control channel. Sekoia researchers noted that each compromised computer is represented by a unique folder derived from a GUID, potentially indicating dozens of infected systems.

See also: Signal phishing attacks target the Ukrainian military

Signal: New APT28 attack distributes BeardShell and Covenant
Signal: New APT28 attack distributes BeardShell and Covenant

Meanwhile, BeardShell—an unmanaged C++ backdoor—appears as the next payload, using the icedrive service for C2 communications. Its entry point, ServiceMain, performs anti-parsing checks and then generates a hardware profile-based identifier for naming directories in the cloud storage.

Once activated, BeardShell creates PowerShell sessions via built-in CLR initialization routines, executing commands in JSON format. These commands and their results are encrypted with ChaCha20-Poly1305 , disguised as innocent image files (e.g., .tiff headers), and uploaded back to the icedrive root directory . The alternative use of legitimate cloud services Koofr and icedrive underscores the adversary’s emphasis on detection avoidance and operational flexibility.

At the heart of this attack is a dual persistence approach. The VBA macro's registry modifications guarantee that the code will execute at startup, while the second-stage DLL's COM hijacking ensures that legitimate printing operations can be seamlessly interposed, masking its presence.

By splitting payload delivery between Office macros, COM hijacking, steganographic shellcode extraction, and legitimate cloud APIs, APT28 achieves a powerful, multi-layered attack. Detection engineers are advised to watch for unexpected COM entries under highly privileged CLSIDs and examine anomalous PNG or TIFF files in AppData directories for hidden payloads.

See also: Signal Windows: Taking screenshots from Recall is prohibited

Signal: New APT28 attack distributes BeardShell and Covenant

With this campaign's reuse of open source frameworks and new steganography, defenders must adapt by correlating code signing anomalies, registry tampering, and cloud API to intercept future intrusions.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS