APT28 Uses Signal Chat to Deploy BEARDSHELL Malware and COVENANT in Ukraine
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-12641 | Command Injection RCE in Roundcube Webmail (CVE-2020-12641) Roundcube Webmail versions before 1.4.4 contain an OS command injection flaw (CWE-78) in rcube_image.php: shell metacharacters in the im_convert_path or im_identify_path configuration settings are not escaped before the configured ImageMagick binaries are executed. When image processing is triggered, an attacker who can control those configuration values can append arbitrary shell commands that run with the privileges of the web server user, yielding full remote code execution on the mail server. Successful exploitation can expose stored email, mail credentials, and the underlying host; the flaw is scored 9.8 (critical), with no privileges or user interaction required per the CVSS vector. Any self-hosted Roundcube deployment older than 1.4.4 is affected, including Roundcube packages shipped by openSUSE Leap and openSUSE Backports for SUSE Linux Enterprise. Exploitation is confirmed in the wild: CISA added it to the KEV catalog on 2023-06-22, EPSS puts the 30-day exploitation probability at ~84%, and headlines note APT28-linked activity targeting government Roundcube servers, including Ukrainian entities. Do: Upgrade Roundcube to 1.4.4 or later, or apply the vendor-patched openSUSE Leap / SLE backport packages, as required by the CISA KEV listing (added 2023-06-22). After patching, verify that im_convert_path and im_identify_path settings contain no unescaped metacharacters and review web server logs for injected command activity; given APT28's targeting of government Roundcube servers, prioritize public-sector mail infrastructure for patching and threat hunting. | 9.8 | 84% | KEV PoC |
| masstens of thousands of internet-exposed Roundcube instances; millions of end users via bundled/self-hosted deployments (estimate) | |
| CVE-2020-35730 | Cross-Site Scripting in Roundcube Webmail Plain-Text Email Link Handling Roundcube Webmail contains a cross-site scripting (XSS) flaw (CWE-79) in the link-reference handling of rcube_string_replacer.php, where the linkref_addindex function mishandles JavaScript embedded in a link element of a plain-text email. An attacker triggers the flaw simply by sending a crafted plain-text message to a victim; when the message is processed/displayed in the Roundcube interface, the embedded script executes in the context of the victim's webmail session. Successful exploitation can lead to session hijacking, theft of webmail cookies or credentials, and arbitrary actions in the victim's mailbox. Any deployment of Roundcube Webmail is affected, which includes self-hosted instances and webmail offered by hosting providers, ISPs, and universities. Although no public proof-of-concept is known, CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2023-06-22, confirming exploitation in the wild; ransomware association is unknown, and no CVSS score is yet available, though EPSS puts 30-day exploitation probability at 32.7% (98th percentile). Do: Apply the vendor's updated Roundcube release per CISA's required action (updates per vendor instructions); since no specific fixed versions appear in this data, install the latest patched release of your deployed 1.x branch and verify with the vendor advisory. Check webmail servers for processing of plain-text messages with link-reference elements and review logs for anomalous webmail sessions; treat KEV-listed status as evidence of active exploitation and prioritize internet-exposed Roundcube instances. | 6.1 | 33% | KEV |
| masslikely >1M users across tens of thousands of exposed instances (Roundcube is bundled as webmail in cPanel/Plesk and by many ISPs) | |
| CVE-2021-44026 | SQL Injection in Roundcube Webmail via Search Parameters Roundcube Webmail contains a SQL injection flaw (CWE-89) in which attacker-controlled 'search' or 'search_params' input is incorporated into database queries without sufficient sanitization. An attacker with access to the webmail search functionality (typically an authenticated mailbox user) can submit crafted parameters to execute arbitrary SQL against the Roundcube backend database, potentially reading or modifying stored mail account data. Any organization running Roundcube is affected, including self-hosted mail servers and customers of hosting providers that ship Roundcube as their bundled webmail client. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-06-22, indicating exploitation in the wild, and EPSS assigns a 41.9% probability of exploitation within 30 days (99th percentile). No public proof-of-concept is known, and CISA lists ransomware use as unknown. Do: Apply vendor updates per Roundcube's instructions by upgrading to the latest patched, supported release, prioritizing internet-facing webmail servers; federal agencies must remediate per the CISA KEV requirement. If Roundcube is managed by a hosting provider (e.g., via cPanel), coordinate patching with them. In the interim, restrict webmail exposure and review database and web logs for anomalous search-related queries that may indicate exploitation. | 9.8 | 42% | KEV |
| massmillions of users across tens of thousands of exposed Roundcube deployments (estimated) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | icedrive.net | ffic associated with the domains "app.koofr[.]net" and "api.icedrive[.]net." The disclosure comes as CERT-UA revealed APT28's target |
| domain | koofr.net | an eye on network traffic associated with the domains "app.koofr[.]net" and "api.icedrive[.]net." The disclosure comes as CERT-U |
Full article735 words · extracted from thehackernews.com · click to collapse
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new cyber attack campaign by the Russia-linked APT28 (aka UAC-0001) threat actors using Signal chat messages to deliver two previously undocumented malware families dubbedd BEARDSHELL and COVENANT.
BEARDSHELL, per CERT-UA, is written in C++ and offers the ability to download and execute PowerShell scripts, as well as upload the results of the execution back to a remote server over the Icedrive API.
The agency said it first observed BEARDSHELL, alongside a screenshot-taking tool named SLIMAGENT, as part of incident response efforts in March-April 2024 in a Windows computer.
While there were no details available on how the infection took place at that time, the agency said it received threat intelligence from ESET more than a year later that detected evidence of unauthorized access to a "gov.ua" email account.
The exact nature of the information shared was not disclosed, but it likely pertains to a report from the Slovak cybersecurity company last month that detailed APT28's exploitation of cross-site scripting (XSS) vulnerabilities in various webmail software such as Roundcube, Horde, MDaemon, and Zimbra to breach Ukrainian government entities.
Further investigation triggered as a result of this discovery unearthed crucial evidence, including the initial access vector used in the 2024 attack, as well as the presence of BEARDSHELL and a malware framework dubbed COVENANT.
Specifically, it has come to light that the threat actors are sending messages on Signal to deliver a macro-laced Microsoft Word document ("Акт.doc"), which, when launched, drops two payloads: A malicious DLL ("ctec.dll") and a PNG image ("windows.png").
The embedded macro also makes Windows Registry modifications to ensure that the DLL is loaded when Windows File Explorer ("explorer.exe") is launched the next time. The primary task of the DLL is to load shellcode from the PNG file, resulting in the execution of the memory-resident COVENANT framework.
COVENANT subsequently downloads two more intermediate payloads that are designed to launch the BEARDSHELL backdoor on the compromised host.
To mitigate potential risks associated with the threat, state organizations are recommended to keep an eye on network traffic associated with the domains "app.koofr[.]net" and "api.icedrive[.]net."
The disclosure comes as CERT-UA revealed APT28's targeting of outdated Roundcube webmail instances in Ukraine to deliver exploits for CVE-2020-35730, CVE-2021-44026, and CVE-2020-12641 via phishing emails that ostensibly contain text about news events but weaponize these flaws to execute arbitrary JavaScript.
The email "contained a content bait in the form of an article from the publication 'NV' (nv.ua), as well as an exploit for the Roundcube XSS vulnerability CVE-2020-35730 and the corresponding JavaScript code designed to download and run additional JavaScript files: 'q.js' and 'e.js,'" CERT-UA said.
"E.js" ensures the creation of a mailbox rule for redirecting incoming emails to a third-party email address, in addition to exfiltrating the victim's address book and session cookies via HTTP POST requests. On the other hand, "q.js" features an exploit for an SQL injection flaw in Roundcube (CVE-2021-44026) that's used to gather information from the Roundcube database.
CERT-UA said it also discovered a third JavaScript file named "c.js" that includes an exploit for a third Roundcube flaw (CVE-2020-12641) to execute arbitrary commands on the mail server. In all, similar phishing emails were sent to the email addresses of more than 40 Ukrainian organizations.
More Details About BEARDSHELL Campaign Emerge
Sekoia, which is tracking the activity under the name Operation Phantom Net Voxel, said it uncovered additional weaponized Office documents shared via Signal that are used to deliver the COVENANT command-and-control (C2) framework and the BEARDSHELL backdoor.
One of COVENANT's components is an HTTP Grunt Stager written in .NET assembly that's designed to establish an API-driven channel to the Koofr cloud infrastructure using a custom outbound C2 protocol by creating a C2Bridge and awaiting additional payloads.
"The analysis of spear-phishing lure documents reveals a consistent focus on Ukrainian military administrative procedures," the French cybersecurity company said. "It suggests targeting of on-the-ground soldiers or personnel embedded within military HR, logistics, or command structures."
"They are highly likely used by Russian military intelligence to gather cyber intelligence on frontline combatants, possibly on specific units in the Ukrainian military theatre. This activity is coherent with GRU mandate and APT28’s previous operations."
(The story was updated after publication on September 17, 2025, with additional insights from Sekoia.)
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/06/apt28-uses-signal-chat-to-deploy.html