Full Report
2025-06-21 • Cert-UA • Cert-UA • win.beardshell, win.slimagent Open article on Malpedia
Analysis Summary
# Threat Actor: UAC-0001 (APT28)
## Attribution & Identity
* **Primary Designation:** UAC-0001
* **Known Aliases/Associations:** APT28 (Stated in the header)
## Activity Summary
The provided context specifically links UAC-0001 (APT28) to cyberattacks targeting public authorities. The activities involve the use of specific malware families, namely BEARDSHELL and COVENANT.
## Tactics, Techniques & Procedures
The article explicitly names the following tooling utilized by the actor:
* BEARDSHELL (Malware)
* COVENANT (Likely a framework or C2 mechanism)
* win.beardshell (Related malware entry)
* win.slimagent (Related malware entry)
*(Note: Specific TTP techniques or MITRE ATT&CK IDs are not detailed in the provided truncated context, only the tools used are listed.)*
## Targeting
* **Sectors:** Public authorities (Government/Public Sector)
* **Geography:** Not explicitly mentioned in the provided context, though the source is Cert-UA, suggesting potential Ukrainian relevance or focus.
* **Victims:** Public authorities.
## Tools & Infrastructure
* **Malware families used:** BEARDSHELL, COVENANT, slimagent.
* **Infrastructure (C2, domains, IPs):** None specified in the provided context.
## Implications
UAC-0001/APT28 remains an active threat actor prioritizing attacks against government and public authority infrastructure, leveraging established custom or modular toolsets like BEARDSHELL and COVENANT for persistence and command/control.
## Mitigations
Defense recommendations specific to this actor are not detailed in the provided summary context. General mitigation should focus on detection and hardening against the identified malware (BEARDSHELL, COVENANT).