logo

Russia-linked espionage campaign targeting Ukraine using Starlink and charity lures

ID: 11b39f24-fc43-5acf-a3c4-dba6a8643ea1

STIX ID: report--11b39f24-fc43-5acf-a3c4-dba6a8643ea1

Feed Name: The Record from Recorded Future News

Threat Score
80/100

Date Published: 2026-03-16

Date Updated: 2026-05-01

...
...

Researchers observed a Russia-linked APT known as Laundry Bear (Void Blizzard) conducting a February cyber-espionage campaign against Ukrainian organizations using documents impersonating a Ukrainian charity and Starlink verification materials to deliver DrillApp spyware. The backdoor, executed via Microsoft Edge, can upload/download files and capture audio, webcam images, and screen recordings; attackers are leveraging browser capabilities and public text-sharing services to evade detection, and analysts characterize the malware as early-stage development.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.