APT28 (Sednit/Fancy Bear), a Russian GRU-linked cyber-espionage group associated with Unit 26165, has been assessed by ESET to have reactivated a more advanced, custom tooling set beginning in April 2024, shifting from a period where its most sophisticated malware was less frequently observed. The activity has focused on long-term surveillance of Ukrainian targets, particularly military personnel, and includes the use of multiple implants: BEARDSHELL (a .NET-based implant used to execute PowerShell commands) and COVENANT (used alongside BEARDSHELL), as well as SLIMAGENT, which performs keylogging, screenshot capture, and clipboard collection. ESET and reporting based on its findings link SLIMAGENT to historical XAgent development, citing code and logging-format similarities consistent with an evolution of APT28’s earlier backdoor ecosystem.
ESET’s reporting indicates the operators use a dual-implant architecture to improve resilience, including leveraging legitimate cloud services for command-and-control; BEARDSHELL was described as using Icedrive as a C2 channel, and the overall approach was characterized as designed to maintain durable access for espionage operations extending through 2025 into 2026. Separate weekly threat-bulletin coverage that mentions unrelated breaches and other threat activity does not add material detail to the APT28/Sednit campaign described above and should not be treated as part of the same incident reporting.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
On March 10, 2026, ESET publicly reported that APT28 had revived an advanced in-house espionage toolkit centered on BeardShell and a heavily modified Covenant framework to target Ukraine.
In January 2026, CERT-UA reported a spearphishing campaign exploiting CVE-2026-21509 to deploy APT28's modified Covenant implant.
Researchers observed APT28 most recently abusing the Filen cloud storage service for Covenant command-and-control beginning in July 2025, after rotating among other providers.
In 2025, ESET saw APT28 using cloud drives controlled through its modified Covenant framework to maintain persistent surveillance of targets over extended periods.
In April 2024, CERT-UA found the SlimAgent implant on a Ukrainian government machine, providing an early public indicator of APT28's renewed custom-malware activity in Ukraine.
Since at least April 2024, APT28/Sednit has run a long-term cyber-espionage operation focused on Ukrainian military personnel using BeardShell, modified Covenant, and related tooling.
During its investigation of a 2024 breach in Ukraine, ESET uncovered the broader use of SlimAgent, BeardShell, and modified Covenant, linking the activity to Sednit/APT28.
ESET reported that Sednit/APT28 had been extensively customizing the open-source Covenant framework since 2023, adapting it for stealthy long-term espionage and cloud-drive-based command and control.
ESET identified artifacts and related samples dating to 2018 that targeted government entities in two European countries, supporting its assessment that SlimAgent evolved from APT28's older XAgent codebase.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcehelpnetsecurity.com
Open sourcewelivesecurity.com
Open sourcedarkreading.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.