SlimAgent is a C++ spyware implant for Windows used by the Russian cyberespionage group APT28, also known as Sednit and Fancy Bear. It records keystrokes, captures screenshots, and collects clipboard data. Its keylogging output uses HTML formatting to distinguish application names, window titles, and captured input. Screenshots are captured through Windows APIs, encrypted using AES and RSA, and stored locally with timestamps.
SlimAgent was discovered on a Ukrainian government computer in April 2024 and publicly documented in June 2025. It has been deployed alongside the BeardShell backdoor, including in attacks against Ukrainian government organizations using social engineering through Signal chats. Code-level similarities in keylogging logic and HTML log formatting link SlimAgent to the keylogger module of APT28’s older X-Agent implant. Related samples sharing its codebase were used against governmental entities in two European countries as early as 2018.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The two pieces of malware have been used recently to target central executive bodies of Ukraine in attacks that exploited the CVE-2026-21509 vulnerability in Microsoft Office via malicious DOC files.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The researchers uncovered these malware families after discovering SlimAgent, a keylogging implant deployed in a Ukrainian government system capable of keystroke capture, clipboard collection, and screenshot capture.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Spear phishing campaigns or the SedKit exploit kit delivered the Seduploader first stage.
“Sednit typically compromises its targets through social engineering over Signal Desktop or WhatsApp Desktop, persuading them to open Trojanized Excel or Word documents. In some cases, the attackers even call their targets to increase the chances of success.”
MITRE ATT&CK techniques ... T1005 Data from Local System BeardShell, Covenant, and SlimAgent collect data from a compromised machine.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/tool in the Sednit/APT28 arsenal; exact function is not described in the provided content.
Collection component used for espionage that captures keystrokes and screenshots, then exfiltrates the results as encrypted image files through the same cloud-based channel.
A keylogger linked by code lineage to X-Agent and found on infrastructure associated with APT28 operations.
键盘记录器,与APT28早期植入程序X-Agent存在直接代码渊源。
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.