Signal

APT28 revives advanced malware to spy on Ukrainian military personnel

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-03-10 00:00 UTCUpdated 2026-03-10 10:55 UTC
rss
cveexploitsmalwarethreat_actorsincident_response
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.
2 top sources shown
Russian military hackers revive advanced malware to spy on Ukraine, researchers say
The Record (Recorded Future News) · News · therecord.media · 2026-03-10 00:00 UTC
limited source diversity in top sources
Overview

Russian state-sponsored hacking group APT28 has reactivated sophisticated malware implants named BEARDSHELL and COVENANT to conduct long-term cyber espionage targeting Ukrainian military personnel.

Entities
ESETBEARDSHELLCOVENANT
Score total
1
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
  • The malware has been active since April 2024, with recent reports highlighting renewed activity.
  • Heightened geopolitical tensions make monitoring APT28's operations critical.
  • Timely awareness supports proactive cybersecurity defenses for Ukrainian military and allied entities.
Why it matters
  • APT28's malware resurgence signals ongoing cyber espionage efforts in the Ukraine conflict.
  • The use of BEARDSHELL and COVENANT enables persistent surveillance of military targets.
  • Understanding these threats aids in strengthening defensive and incident response measures.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
  • APT28 uses BEARDSHELL and COVENANT malware to spy on Ukrainian military personnel since April 2024
How sources frame it
  • The Hacker News: neutral
  • The Record (Recorded Future News): neutral
All evidence
All evidence
APT28 Uses BEARDSHELL and COVENANT Malware to Spy on Ukrainian Military
thehackernews · thehackernews.com · 2026-03-10 10:55 UTC
Russian military hackers revive advanced malware to spy on Ukraine, researchers say
The Record (Recorded Future News) · therecord.media · 2026-03-10 00:00 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
  • thehackernews (1)
  • The Record (Recorded Future News) (1)
Top origin domains (this list)
  • thehackernews.com (1)
  • therecord.media (1)