logo

Russian hackers deploy new malware in phishing campaign targeting Ukraine

ID: 20c948f7-8dd6-5899-b4d4-0979e2020afd

STIX ID: report--20c948f7-8dd6-5899-b4d4-0979e2020afd

Feed Name: The Record from Recorded Future News

Threat Score
85/100

Date Published: 2026-03-04

Date Updated: 2026-05-01

...
...

ClearSky researchers identified a suspected Russian state-aligned espionage campaign targeting Ukraine that uses phishing emails with ZIP attachments containing a malicious Ukrainian-language document which installs the BadPaw loader and the MeowMeow backdoor; MeowMeow can read, write, and delete files and evades analysis by checking for virtual machines and common security tools. ClearSky attributes the activity with high confidence to a Russian state-aligned actor and with low confidence to APT28, and CERT‑UA separately reported a related campaign using ShadowSniff and SalatStealer.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.