In late summer 2025, cybersecurity researchers uncovered a sophisticated spearphishing campaign, APT28, targeting Ukrainian military personnel via the Signal messaging platform. The operation, codenamed “Phantom Net Voxel,” begins with a malicious Office document sent through private conversations on Signal, pretending to be urgent administrative forms or compensation claims.
See also: Signal: Secure backups to save & restore conversations

Upon opening, the document's embedded macros drop a hidden DLL and a PNG file onto the victim's computer, starting a multi-layered infection chain that eventually installs both HTTP Grunt Stager and the custom BeardShell backdoor in C++.
Sekoia analysts identified the stealthy appearance of decoy documents, formatted with authentic Ukrainian military nomenclature, as a key element of the campaign’s success. The initial Document_Open macro verifies Windows versions and then uses the CreateProcessW API to register a malicious COM server under CLSID {2227A280-3AEA-1069-A2DE-08002B30309D}, ensuring that the DLL is loaded on every user logon.
If the registry key does not exist, the macro drops prnfldr.dll into the ProgramData directory and windows.png into AppData, hiding both files before calling regsvr32.exe /n /i to perform the DLL installation process.
Once loaded into explorer.exe, the second-stage DLL extracts a shellcode from the least significant bits of each PNG pixel. The embedded shellcode initializes the .NET Common Language Runtime (CLR) and injects a Covenant HTTP Grunt module, which communicates with the Koofr cloud to create directories named “Keeping” and “Transferring”. Hybrid encryption secures communications as file uploads and downloads provide a hidden command and control channel. Sekoia researchers noted that each compromised computer is represented by a unique folder derived from a GUID, potentially indicating dozens of infected systems.
See also: Signal phishing attacks target the Ukrainian military

Meanwhile, BeardShell—an unmanaged C++ backdoor—appears as the next payload, using the icedrive service for C2 communications. Its entry point, ServiceMain, performs anti-parsing checks and then generates a hardware profile-based identifier for naming directories in the cloud storage.
Once activated, BeardShell creates PowerShell sessions via built-in CLR initialization routines, executing commands in JSON format. These commands and their results are encrypted with ChaCha20-Poly1305 , disguised as innocent image files (e.g., .tiff headers), and uploaded back to the icedrive root directory . The alternative use of legitimate cloud services Koofr and icedrive underscores the adversary’s emphasis on detection avoidance and operational flexibility.
At the heart of this attack is a dual persistence approach. The VBA macro's registry modifications guarantee that the code will execute at startup, while the second-stage DLL's COM hijacking ensures that legitimate printing operations can be seamlessly interposed, masking its presence.
By splitting payload delivery between Office macros, COM hijacking, steganographic shellcode extraction, and legitimate cloud APIs, APT28 achieves a powerful, multi-layered attack. Detection engineers are advised to watch for unexpected COM entries under highly privileged CLSIDs and examine anomalous PNG or TIFF files in AppData directories for hidden payloads.
See also: Signal Windows: Taking screenshots from Recall is prohibited

With this campaign's reuse of open source frameworks and new steganography, defenders must adapt by correlating code signing anomalies, registry tampering, and cloud API to intercept future intrusions.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
