Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

APT28 With Weaponized Office Documents Delivers BeardShell and Covenant Modules

In mid-2025, APT28 initiated a spear-phishing campaign utilizing weaponized Office documents to deploy two new payloads: BeardShell, a C-based backdoor, and Covenant’s HTTP Grunt Stager. BeardShell employs IceDrive for command-and-control, while the…

In mid-2025, APT28 initiated a spear-phishing campaign utilizing weaponized Office documents to deploy two new payloads: BeardShell, a C-based backdoor, and Covenant’s HTTP Grunt Stager. BeardShell employs IceDrive for command-and-control, while the Covenant Stager uses the Koofr cloud API for communication.

The campaign involves distributing malicious documents through private Signal chats. These documents bypass Microsoft Office security by exploiting the absence of Mark-of-the-Web protection.

The campaign targets users with documents that resemble internal legal or administrative notifications, urging them to open embedded files containing macros. When opened, these documents execute a VBA macro that performs environment checks, deobfuscates payloads, and establishes persistence.

As noted by Sekoia analysts, the primary macro conducts a COM hijack by placing a DLL (prnfldr.dll) and a benign-looking PNG file (windows.png) in the system. The macro registers the DLL under the CLSIDPrinters registry key and uses regsvr32.exe to initiate the DLL's installation routine, ensuring execution without reboot.

Once activated by Explorer.exe, prnfldr.dll proxies print functions and initiates a secondary thread to extract AES-encrypted shellcode from the PNG file. This method embeds metadata, a key, IV, and encrypted content within the image data.

BeardShell employs IceDrive for command-and-control, while the Covenant Stager uses the Koofr cloud API for communication.
Harper Fairbanks · Thehackingpost

Decryption of the shellcode initializes the Common Language Runtime and loads the Covenant .NET assembly, establishing an HTTP-based C2 channel with Koofr infrastructure.

The secondary stage employs digital steganography to read the PNG file, extract the payload, and execute the Covenant Grunt Stager:

HRESULT hr; ICLRMetaHost pMetaHost = NULL; pMetaHost->GetRuntime(L"v4.0.30319", IID_ICLRRuntimeInfo, (LPVOID)&pRuntimeInfo); pRuntimeInfo->GetInterface(CLSID_CorRuntimeHost, IID_ICorRuntimeHost, (LPVOID*)&pCorRuntimeHost); pCorRuntimeHost->Start(); pCorRuntimeHost->ExecuteInDefaultAppDomain(L"C:\\path\\GruntHTTPStager.dll", L"EntryPoint", L"Execute", NULL, &hr);

Through Koofr’s API, Covenant’s HTTP Grunt module uploads reconnaissance data and downloads new modules using hybrid encryption for session keys.

Advertisement

BeardShell operates as a C DLL, loading the System.Management.Automation assembly. It interfaces via JSON for PowerShell commands, polling an IceDrive directory every four hours for command execution.

{"taskid":0,"cmdid":2,"data":{"id":0,"cmd":"ipconfig /all"}}

This dual-payload strategy highlights APT28's use of open-source frameworks and cloud services for covert operations. Embedding steganographic payloads and using multiple cloud channels complicates detection, emphasizing the need for advanced steganography detection and cloud API monitoring.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories