Russia-linked threat group Sednit (APT28/Fancy Bear) has resumed sophisticated cyberespionage operations targeting Ukrainian military personnel after years of using simple implants. ESET researchers uncovered two new malware tools: BeardShell, a PowerShell interpreter that uses the legitimate cloud service Icedrive for C2 communications, and Covenant, a heavily modified open-source .NET post-exploitation framework supporting over 90 espionage functions. Both tools share code lineage with older Sednit malware from the 2010s, suggesting the same development team has continued evolving the toolkit. The group uses social engineering via Signal and WhatsApp Desktop to deliver trojanized Office documents, and their use of legitimate cloud infrastructure for C2 makes detection and blocking significantly harder.