Signal Comes Under Siege as APT28 Deploys eardShell and Covenant in Its Latest Campaign

Russian state-sponsored threat actor APT28 has launched a sophisticated cyber espionage campaign targeting Ukrainian military personnel through weaponized Signal conversations, deploying advanced malware, including the newly discovered BeardShell backdoor, and leveraging the Covenant red-team framework for covert operations.

Security researchers from Sekoia.io revealed that the campaign, active since early 2025, begins with spearphishing attacks conducted through private Signal chats where attackers impersonate colleagues or superiors to distribute malicious Office documents.

These communications create false urgency around compensation decisions and legal threats, manipulating targets into opening weaponized files containing Ukrainian military administrative forms.

The infection chain demonstrates remarkable technical sophistication, employing multiple stages of payload delivery and novel obfuscation techniques. Initial malicious Office documents contain VBA macros that implement user-level COM hijacking to load a malicious DLL.

APT28 eardShell
Covenant & Koofr interaction – Directories creation

This secondary payload extracts shellcode hidden within legitimate PNG files using steganographic techniques a method never before observed in APT28 operations.

Advanced C2 Infrastructure and Encryption

The campaign’s most innovative aspect involves abusing legitimate cloud storage services for command and control communications.

APT28 operators customized the open-source Covenant framework to communicate through Koofr and Icedrive APIs, creating an encrypted communication channel that appears as regular cloud storage traffic.

BeardShell, the campaign’s primary backdoor written in C++, establishes persistence through registry manipulation and executes PowerShell commands received from its Icedrive-based C2 infrastructure.

APT28 eardShell
Overall infection chain

The malware utilizes ChaCha20-Poly1305 authenticated encryption to protect communications and masquerades malicious files with fake headers that mimic legitimate image formats, including BMP, GIF, JPEG, PNG, and TIFF.

Researchers identified 42 unique compromised hosts with activity dating back to December 2024, recovering 115 files across multiple cloud storage volumes.

The operation targets explicitly Ukrainian military command structures, focusing on personnel reports, medical compensation requests, and logistical documentation related to drone deployments.

Attribution analysis confirms the campaign’s connection to Russia’s General Staff Main Intelligence Directorate (GRU), specifically the 85th Main Special Service Centre of Military Unit 26165.

This assessment aligns with APT28’s historical targeting patterns and represents a significant technical evolution for the group, known by aliases including Sofacy, Fancy Bear, and Forest Blizzard.

The campaign has demonstrated adaptability, with researchers observing continued evolution through August 2025, including expansion to additional cloud services like Filen and deployment via weaponized Excel documents.

The integration of legitimate cloud infrastructure with advanced encryption techniques presents significant detection challenges for traditional security monitoring systems.

Defense teams should monitor for unusual Office macro activity, COM object manipulation, and abnormal cloud storage API usage patterns.

Organizations should implement enhanced scrutiny of Signal communications and maintain updated detection rules for steganographic payload techniques targeting PNG files.

Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates

Priya
Priya
Priya is a Security Reporter who tracks malware campaigns, exploit kits, and ransomware operations. Her reporting highlights technical indicators and attack patterns that matter to defenders

Trending News

Related Stories