The Russian state-run group APT28 is using the BEARDSHELL and COVENANT malware as part of a long-running cyberespionage campaign targeting Ukrainian military personnel .

According to ESET , the two malware families have been in use since April 2024. APT28, also known as Blue Athena, BlueDelta, Fancy Bear, Fighting Ursa, Forest Blizzard (formerly Strontium), FROZENLAKE, Iron Twilight, ITG05, Pawn Storm, Sednit, Sofacy, and TA422, is a state-owned entity affiliated with Unit 26165 of the Russian Federation's GRU military intelligence agency .
The malware used by APT28
The group's malware arsenal includes BEARDSHELL, COVENANT, and another program codenamed SLIMAGENT, which is capable of logging keystrokes, capturing screenshots, and collecting clipboard data.
See also: Malicious npm package impersonates OpenClaw and deploys RAT
SLIMAGENT was first publicly documented by the Computer Emergency Response Team of Ukraine (CERT-UA) in June 2025. SLIMAGENT has its roots in XAgent, another malware used by APT28 in the 2010s to facilitate remote control and data exfiltration. This is based on code similarities discovered between SLIMAGENT and previously unknown samples deployed in attacks against government entities in 2018.
It is estimated that the 2018 artifacts and the 2024 SLIMAGENT sample originated from XAgent, with ESET's analysis revealing overlaps in keylogging between SLIMAGENT and an XAgent sample.
Along with SLIMAGENT, another backdoor is being deployed, referred to as BEARDSHELL, which is capable of executing PowerShell commands on compromised computers. It uses the legitimate cloud storage service Icedrive for command and control (C2).

A notable feature of the malware is that it uses a discreet obfuscation technique referred to as an opaque predicate and is also found in XTunnel (also known as X-Tunnel), a network traversal and pivoting tool used by APT28 in the 2016 attack on the Democratic National Committee (DNC). The tool provides a secure tunnel to an external C2 server.
See also: Hacker exploits .arpa domain to bypass phishing detection
“The shared use of this rare obfuscation technique, combined with its coexistence with SLIMAGENT, leads us to conclude that BEARDSHELL is part of Sednit’s customized arsenal,” ESET added.
A third important tool of the team is COVENANT, an open-source .NET post-exploitation framework that has been modified to support long-term espionage and implement a new cloud-based network protocol that abuses the Filen cloud storage service for C2 (as of July 2025).

Previously, the COVENANT variant of APT28 reportedly used pCloud (in 2023) and Koofr (in 2024-2025).
See also: ShinyHunters claim to be stealing data from Salesforce Aura
In 2021, Trellix revealed that APT28 developed Graphite, a backdoor that used OneDrive for C2 and PowerShell Empire in attacks targeting high-ranking government officials in West Asia.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
