SlimAgent is a C++ spyware/keylogger attributed with high confidence to APT28 (Sednit/Fancy Bear/Forest Blizzard/Sofacy), a GRU-linked Russian espionage actor. It was discovered on a Ukrainian government system in April 2024, and related samples from 2018 targeting governmental entities in two European countries were assessed by ESET to come from the same codebase. Multiple sources state SlimAgent has direct code lineage to APT28’s older X-Agent/Xagent keylogging module, including shared keylogging logic and matching HTML log formatting/color scheme.
Its documented capabilities include keystroke logging, screenshot capture, and clipboard collection. Reporting also states it can capture screenshots via Windows APIs, encrypt collected screenshots with AES and RSA, and store them locally using timestamped filenames; some descriptions note exfiltration of collected data as encrypted image files through the same cloud channels used by associated APT28 tooling. SlimAgent has been described as a simple but efficient spying tool and as a standalone espionage implant.
SlimAgent has been observed on the same operator infrastructure as other APT28 malware, notably BeardShell and modified Covenant/Grunt tooling, and was referenced in reporting on Operation Phantom Net Voxel. CERT-UA publicly documented SlimAgent in 2025 and reported related activity in which Signal chats were used to deliver BeardShell and SlimAgent to Ukrainian government organizations. Broader reporting ties the surrounding campaigns primarily to Ukrainian government and military targets, with long-term surveillance of Ukrainian personnel as an objective. Reported identifiers include internal name RemoteKeyLogger.dll in older related samples, ESET-listed filename eapphost.dll, SHA-1 5603E99151F8803C13D48D83B8A64D071542F01B, and detection name Win64/Spy.KeyLogger.LS.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The two pieces of malware have been used recently to target central executive bodies of Ukraine in attacks that exploited the CVE-2026-21509 vulnerability in Microsoft Office via malicious DOC files.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
we find 2 APT28 samples that are not PixyNetLoader: 9faeb1c8a4b9827f025a63c086d87c409a369825428634b2b01314460a332c6c APT28 SlimAgent
The researchers uncovered these malware families after discovering SlimAgent, a keylogging implant deployed in a Ukrainian government system capable of keystroke capture, clipboard collection, and screenshot capture.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Spear phishing campaigns or the SedKit exploit kit delivered the Seduploader first stage.
“Sednit typically compromises its targets through social engineering over Signal Desktop or WhatsApp Desktop, persuading them to open Trojanized Excel or Word documents. In some cases, the attackers even call their targets to increase the chances of success.”
MITRE ATT&CK techniques ... T1005 Data from Local System BeardShell, Covenant, and SlimAgent collect data from a compromised machine.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Collection component used for espionage that captures keystrokes and screenshots, then exfiltrates the results as encrypted image files through the same cloud-based channel.
A keylogger linked by code lineage to X-Agent and found on infrastructure associated with APT28 operations.
键盘记录器,与APT28早期植入程序X-Agent存在直接代码渊源。
A C++ keylogger associated with Operation Phantom Net Voxel and linked by researchers to historical X-Agent code lineage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.