Skip to content

Malware

BEARDSHELL

According to CERT-UA, this is a malware developed using the C++ programming language.

BEARDSHELL is a Windows malware family operated by APT28.

Background

CERT-UA reports that this family is written in C++. Its features include retrieving payloads, decrypting them with chacha20-poly150, running PowerShell scripts, and sending the output of executed commands back to the operators.


Source: Malpedia (Fraunhofer FKIE).