APT28 Targets Government Agencies with BEARDSHELL and COVENANT

Red | Attack Report
Download PDF

APT28 (UAC-0001), a Russian state-linked group, targeted government agencies with a sophisticated cyberattack using spear-phishing emails to deliver malicious documents via Signal. The attack deployed BEARDSHELL and COVENANT malware, enabling remote access and data exfiltration through trusted cloud services. By leveraging fileless techniques and legitimate platforms, the attackers evaded detection and maintained persistent control over compromised systems. This campaign highlights the evolving tactics of APT28 in targeting critical government infrastructure.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox

Cyber Horizons 2025

What Last Year’s Attacks Reveal About Today’s Risks

Watch the Webinar on-demand and get a FREE copy of our Cyber Horizons 2025 report.

Our Speakers
Speaker 1

Prateek Bhajanka Global Field CISO & Former Gartner Analyst Hive Pro Inc.

Speaker 2

Ankit Mani Manager Threat Intel HiveForce Labs

Speaker 3

Sreevani Tonipe Senior Threat Researcher HiveForce Labs