APT28 hackers use Signal chats to launch new malware attacks on Ukraine

APT28 hackers use Signal chats to launch new malware attacks on Ukraine

Russian state-sponsored group APT28 is leveraging Signal chats to deliver novel malware families, BeardShell and SlimAgent, targeting Ukrainian government entities. The attacks involve using encrypted messaging for phishing and infiltration, highlighting evolving tactics in cyberespionage. #APT28 #BeardShell #SlimAgent #UkrainianGovernment

Keypoints

  • APT28 is utilizing Signal messaging platform for targeted cyberattacks in Ukraine.
  • The malware families BeardShell and SlimAgent were newly identified during recent investigations.
  • The malware uses macros, memory-resident backdoors, and persistence techniques like COM-hijacking.
  • Signal’s platform is exploited for spear-phishing, account hijacking, and malware delivery.
  • Ukraine officials reported cooperation issues with Signal despite the platform’s encrypted security features.

Read More: https://www.bleepingcomputer.com/news/security/apt28-hackers-use-signal-chats-to-launch-new-malware-attacks-on-ukraine/