Signal
APT28 revives advanced malware to spy on Ukrainian military personnel
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-03-10 00:00 UTCUpdated 2026-03-10 10:55 UTC
rss
cveexploitsmalwarethreat_actorsincident_response
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.2 top sources shown
limited source diversity in top sources
Overview
Russian state-sponsored hacking group APT28 has reactivated sophisticated malware implants named BEARDSHELL and COVENANT to conduct long-term cyber espionage targeting Ukrainian military personnel.
Entities
ESETBEARDSHELLCOVENANT
Score total
1
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
- The malware has been active since April 2024, with recent reports highlighting renewed activity.
- Heightened geopolitical tensions make monitoring APT28's operations critical.
- Timely awareness supports proactive cybersecurity defenses for Ukrainian military and allied entities.
Why it matters
- APT28's malware resurgence signals ongoing cyber espionage efforts in the Ukraine conflict.
- The use of BEARDSHELL and COVENANT enables persistent surveillance of military targets.
- Understanding these threats aids in strengthening defensive and incident response measures.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
- APT28 uses BEARDSHELL and COVENANT malware to spy on Ukrainian military personnel since April 2024
How sources frame it
- The Hacker News: neutral
- The Record (Recorded Future News): neutral
All evidence
All evidence
APT28 Uses BEARDSHELL and COVENANT Malware to Spy on Ukrainian Military
thehackernews · thehackernews.com · 2026-03-10 10:55 UTC
Russian military hackers revive advanced malware to spy on Ukraine, researchers say
The Record (Recorded Future News) · therecord.media · 2026-03-10 00:00 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
- thehackernews (1)
- The Record (Recorded Future News) (1)
Top origin domains (this list)
- thehackernews.com (1)
- therecord.media (1)