Image for Article: APT28 hackers deploy customized variant of Covenant open-source tool

Article Details

Title
Article: APT28 hackers deploy customized variant of Covenant open-source tool
Impact Score
5 / 10
AI Summary (Processed Content)

The Russian state-sponsored hacking group APT28 is using a custom, modified version of the open-source Covenant framework alongside a newer implant called BeardShell for long-term espionage, primarily targeting Ukrainian government and military entities. These tools leverage cloud storage services for communication and exploit software vulnerabilities for initial access. The group employs a dual-implant strategy, with Covenant as the primary tool and BeardShell as a fallback, indicating advanced and persistent development efforts. The main topics covered are a specific cyber espionage campaign, the malware tools and techniques used, and the attribution to the APT28 threat group.

Original URL
https://www.bleepingcomputer.com/news/security/apt28-hackers-deploy-customized-variant-of-covenant-open-source-tool/
Source Feed
BleepingComputer
Published Date
2026-03-10 10:00
Fetched Date
2026-03-10 07:45
Processed Date
2026-03-10 07:45
Embedding Status
Present
Cluster ID
Not Clustered
Raw Extracted Content