- The Mess: Russia-linked APT28 has revived an older espionage toolkit to target Ukrainian military personnel and other high-value targets. Researchers say the campaign combines long-running malware with newer infrastructure and techniques to maintain covert access.
This isn’t a brand-new zero-day.
That’s precisely why it’s interesting.
APT28 — also known as Fancy Bear / Forest Blizzard — is reusing and evolving tools that have been around for years instead of constantly throwing away its arsenal.
According to ESET research reported by The Record, the group has been using malware including BEARDSHELL, COVENANT and SLIMAGENT in operations against Ukrainian targets, including military personnel.
Old Malware, New Targets
SLIMAGENT is particularly interesting.
The malware can capture:
- keystrokes;
- screenshots;
- clipboard contents;
- application information.
Researchers found code similarities between SLIMAGENT and older APT28 tooling, including XAgent, suggesting that the attackers are recycling parts of an established malware ecosystem rather than starting from zero every time.
For defenders, that creates an unpleasant problem.
Old indicators don’t necessarily mean an old campaign.
APT28 can take an existing implant, modify its delivery mechanism and infrastructure, and put it back into service.
The Group Is Still Targeting Ukraine
The current activity is focused heavily on Ukrainian targets, particularly military-related personnel.
That fits APT28’s established mission.
The group is widely attributed to Unit 26165 of Russia’s GRU military intelligence service and has spent years targeting government, military and diplomatic organizations.
But the campaign isn’t necessarily stopping at Ukraine.
Recent APT28 activity has also targeted European organizations involved in maritime transport, logistics and government operations, including entities in Poland, Slovenia, Turkey, Greece and Ukraine.
That makes the campaign relevant far beyond the immediate battlefield.
The Interesting Part Is the Evolution
APT28 has repeatedly demonstrated that it can weaponize newly disclosed vulnerabilities quickly.
One recent campaign exploited CVE-2026-21509, a Microsoft Office vulnerability, against government and military targets in Europe and Ukraine. Researchers observed the group weaponizing the flaw shortly after disclosure.
But at the same time, the group continues using older malware.
That’s a useful lesson:
new vulnerability + old malware = perfectly viable attack.
Attackers don’t care whether their tooling is five years old if it still works.
Why This Matters to Defenders
Security teams often build detection around the latest threat reports.
New CVE.
New malware.
New domain.
New hash.
Then the campaign changes.
APT28’s approach demonstrates why defenders need to look at behavior, not just indicators.
A malware hash can change.
A C2 domain can disappear.
A phishing document can be regenerated.
But suspicious behavior such as:
unexpected Office → external connection
credential access
unusual screenshot capture
persistent outbound C2
abnormal clipboard access
is much harder to hide completely.
The Fix
Organizations handling sensitive government, military, transport or critical-infrastructure information should monitor for known APT28 behaviors and keep endpoint, Office and network telemetry enabled.
Patch externally exposed software quickly.
Restrict unnecessary outbound connections.
Protect privileged credentials.
And don’t throw away older detection rules simply because the malware they target is no longer making headlines.
Old malware doesn’t mean dead malware.
Bugstoday Opinion
APT28 doesn’t need to reinvent itself every month.
That’s the point.
The group can recycle proven components, change the delivery mechanism and continue hunting the same kinds of targets.
For defenders, that makes attribution less important than visibility.
You don’t need to know that Fancy Bear is sitting behind the keyboard to notice that a supposedly ordinary workstation suddenly starts logging keystrokes, capturing screenshots and talking to an unfamiliar command server.
Bugstoday verdict: APT28 is proving that cyberespionage doesn’t need shiny new malware. A proven toolkit, a new target and enough patience can be more than enough. The dangerous part isn’t that the old tools came back — it’s that they still work.




