The Invisible Thief: How One Spy Tool Evaded Detection for Years
Mar 10, 2026 // 15:24 - Lina Schonbein


Researchers have highlighted several long-standing or sophisticated spy tools that have been quietly exfiltrating data, most notably the resurgence of the Sednit (also known as APT28 or Fancy Bear) espionage toolkit. 

1. Sednit’s Modern Espionage Toolkit

ESET researchers recently uncovered a modern toolkit used by the Russian state-linked group Sednit. This group has been active since at least 2004, but its latest operations use a dual-implant architecture to maintain years of persistent access. 

  • BeardShell & Covenant: These are two complementary implants. Covenant, an open-source post-exploitation framework, has been heavily modified by Sednit over several years to become their primary espionage tool.
  • Capabilities: These tools log keystrokes, capture screenshots, and collect clipboard data.
  • Stealth: They rely on separate cloud providers for operational resilience, allowing them to monitor high-value targets for more than six months at a time without detection. 

2. Salt Typhoon & Global Telecom Infiltration

A massive hacking campaign by the Chinese-linked group Salt Typhoon was reported in March 2026 to have successfully breached some of the world’s largest phone and internet companies. 

  • Scale: The group has reportedly stolen tens of millions of phone records, specifically targeting senior government officials.
  • Persistence: The operation is described as one of the broadest and most sustained hacking campaigns in recent years. 

3. Agent Tesla: The Persistent Credential Stealer

First identified in 2014, Agent Tesla remains one of the most dangerous and quietly effective spy tools in 2026. 

  • Evolution: Originally a simple keylogger, it has evolved into a complex Remote Access Trojan (RAT) that can capture screenshots, sniff browser data, and even record audio and video from infected devices.
  • Long-Term Impact: It is frequently used to quietly steal credentials from small and mid-sized businesses, often going undetected for long periods. 

4. Memory-Harvesting Malware 

A new trend in 2026 is the rise of memory-harvesting malware, which steals secrets directly from RAM rather than the hard drive. 

  • Invisible Theft: This malware leaves no files on disk and disappears when a device is rebooted, making it almost impossible for traditional forensic tools to detect.
  • Targeting: It extracts decrypted data like session tokens, API keys, and even content from secure messaging apps like WhatsApp and Slack while the apps are in use.

#detection  #evaded  #for  #how  #invisible  #news  #one  #spy  #the  #thief:  #tool  #years   —   News