Threats · 189 days ago
ESET links Sednit (Unit 26165/GRU) to an espionage campaign active since April 2024. Operators used SlimAgent, BeardShell and Covenant to collect keystrokes, screenshots and clipboard data via cloud-hosted C2. Hunt indicators, isolate infected hosts and review cloud-storage logs.
3 sources covering this story
Russian Threat Actor Sednit Resurfaces With Sophisticated Toolkit
After several years of using simple implants, the Russia-affiliated threat actor is back with two new sophisticated malware tools.
This spy tool has been quietly stealing data for years - Help Net Security
ESET researchers uncover the Sednit espionage toolkit targeting Ukrainian military personnel with two advanced implants since April 2024.
Sednit reloaded: Back in the trenches
ESET researchers document how the Sednit APT group has reemerged with a modern toolkit centered on two paired implants – BeardShell and Covenant.
Part of the PlainSec briefing for 2026-03-12