BeardShell is a custom C++ backdoor for Windows used by the Russian state-sponsored cyberespionage group APT28, also known as Sednit, Fancy Bear, and Forest Blizzard. Observed in operations since April 2024, it supports long-term access to Ukrainian governmental and military systems. Targets have also included drone manufacturers and organizations involved in drone research and development.
BeardShell downloads and decrypts PowerShell scripts, executes them within a .NET runtime environment, and returns execution results through the legitimate Icedrive cloud storage service. It replicates communications used by the official Icedrive client to implement cloud-based command and control. Its tasking uses ChaCha20-Poly1305 encryption, and system-derived identifiers distinguish infected hosts. BeardShell employs rare opaque-predicate obfuscation also found in APT28’s older Xtunnel tool, providing a technical link to the group’s established custom arsenal.
APT28 commonly deploys BeardShell alongside a heavily modified Covenant implant, using separate cloud providers to improve operational resilience. Covenant serves as the primary espionage implant, while BeardShell provides fallback access and can redeploy Covenant. Associated infection chains use malicious Office documents delivered through spearphishing and messaging applications, staged loaders, and image-concealed payloads. Deployments have used COM hijacking for persistence. BeardShell’s cloud-based communications and code obfuscation help conceal malicious activity within legitimate service traffic and complicate detection and infrastructure disruption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attackers weaponized a newly disclosed Microsoft Office 1-day (CVE-2026-21509) within 24 hours of its public revelation... CVE-2026-21509, a Microsoft Office security feature bypass vulnerability... allows embedded OLE objects to execute by leveraging the WebDAV protocol to fetch external payloads from attacker-controlled infrastructure.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
a new backdoor called BeardShell ... written in C++, establishes persistence, executes PowerShell commands, and hides files under fake image headers.
Researchers at cybersecurity company ESET noticed that since April 2024, the Russian group has started using in attacks two implants named BeardShell and Covenant.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK techniques ... T1583.006 Acquire Infrastructure: Web Services BeardShell relies on Icedrive cloud storage. Covenant relies on Filen cloud storage.
Spear phishing campaigns or the SedKit exploit kit delivered the Seduploader first stage.
APT28’s attack begins with spear-phishing emails containing weaponized documents that exploit CVE-2026-21509... They noted that the APT28 adversary orchestrated a concentrated 72-hour spear-phishing campaign... delivering at least 29 distinct emails across nine Eastern European nations.
The researchers detailed that the malware establishes persistence by hijacking a COM object and briefly creating a scheduled task, ‘OneDriveHealth,’ to restart explorer[dot]exe and trigger the malicious load before deleting itself.
BeardShell is a sophisticated implant capable of executing PowerShell commands within a .NET runtime environment...
MITRE ATT&CK techniques ... T1129 Shared Modules BeardShell and SlimAgent are full-fledged DLL files.
The attackers moved quickly, weaponizing a newly disclosed Microsoft Office one-day vulnerability, CVE-2026-21509, within 24 hours of its public disclosure... When victims open these malicious documents, the exploit triggers automatically without requiring macros or user interaction.
The researchers detailed that the malware establishes persistence by hijacking a COM object and briefly creating a scheduled task, ‘OneDriveHealth,’ to restart explorer[dot]exe and trigger the malicious load before deleting itself.
MITRE ATT&CK techniques ... T1027 Obfuscated Files or Information BeardShell Icedrive token decryption is obfuscated.
Стеганография (T1027.003) прячет payload от файлового анализа: PNG с шеллкодом - не исполняемый файл...
BeardShell uses lightweight anti-analysis checks to evade sandboxes, decrypts embedded strings, and dynamically resolves Windows APIs.
The entire chain is designed for resilience and evasion, utilizing encrypted payloads, legitimate cloud services for C2, in-memory execution, and process injection to minimize forensic artifacts.
MITRE ATT&CK techniques ... T1140 Deobfuscate/Decode Files or Information BeardShell decrypts its strings.
MITRE ATT&CK techniques ... T1480 Execution Guardrails BeardShell only executes in taskhost.exe or taskhostw.exe. SlimAgent only executes in explorer.exe.
MITRE ATT&CK techniques ... T1001 Data Obfuscation BeardShell exfiltrates data in fake images.
The extracted shellcode, ultimately, is used to load an embedded .NET assembly, which is nothing but a Grunt implant associated with the open source .NET COVENANT command-and-control (C2) framework.
在"Operation Phantom Net Voxel"行动中,该组织部署了一个名为BeardShell的定制C++后门,使用云存储API作为其命令通道。
BeardShell ... leverages the legitimate cloud storage service Icedrive as its C&C channel... Previously, in 2023, Sednit’s Covenant abused the legitimate cloud service pCloud, and in 2024–2025, Koofr ... Figure 11 shows the classes introduced by Sednit developers to communicate with the Filen cloud provider, used since July 2025.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware in the Sednit/APT28 toolset; later content explicitly ties it to attacks on public authorities and describes related tooling in the intrusion set.
Implant/backdoor used in the APT28 campaign to extract C2 addresses from steganographic PNG images stored in cloud services and communicate over HTTPS via Icedrive API with additional ChaCha20-Poly1305 encryption layered over TLS.
A custom C++ backdoor that uses a legitimate cloud storage API as its command-and-control channel to blend malicious traffic with trusted cloud service activity.
定制C++后门,使用合法云存储API作为命令与控制通道以规避检测。
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.