Reporting highlighted multiple state-sponsored espionage operations, including a China-linked campaign attributed to Camaro Dragon targeting entities in Qatar with conflict-themed phishing lures that install the PlugX backdoor. The activity was observed rapidly following a new Middle East escalation, using war-related decoy documents and parallel infection chains with differing delivery methods and payloads, indicating more than one operator set involved and underscoring how quickly geopolitical events are operationalized for access and collection.
Separately, Russia’s APT28 (aka Fancy Bear/Forest Blizzard/Sednit) was reported using a heavily modified variant of the open-source Covenant post-exploitation framework alongside implants such as BeardShell and SlimAgent in long-term espionage against Ukrainian targets. The tradecraft described includes exploitation of CVE-2026-21509 via malicious Microsoft Office documents and command-and-control over legitimate cloud services (e.g., Icedrive), consistent with stealth-focused persistence and surveillance operations against government and military-related environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
ESET disclosed that APT28 is deploying BeardShell and a heavily modified Covenant framework, including cloud-based command-and-control and host-specific customization, and assessed that the group's advanced malware development activity resumed in 2024.
Check Point reported that the Qatar operation involved two distinct infection campaigns with different delivery mechanisms and payloads, suggesting at least two separate actor clusters operating at the same time.
During its Ukraine-focused operations, APT28 used malicious DOC files exploiting CVE-2026-21509 in Microsoft Office to compromise targets.
On March 1, 2026, a Chinese-linked espionage operation targeted organizations in Qatar using conflict-themed lures delivered through two parallel infection chains that installed either PlugX or Cobalt Strike.
New hostilities in the Middle East began one day before the Qatar campaign, providing the geopolitical backdrop for war-themed lure documents referencing 'Operation Epic Fury.'
The Qatar-focused campaign was linked to delivery techniques previously observed in December 2025 against Turkish military targets, indicating earlier regional use of the same tradecraft.
Since April 2024, the Russian state-sponsored APT28 group has used BeardShell and a customized Covenant variant to conduct long-term espionage against Ukrainian military personnel and central executive bodies of Ukraine.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.