Russian hackers deploy new malware in phishing campaign targeting Ukraine
ID: 20c948f7-8dd6-5899-b4d4-0979e2020afd
STIX ID: report--20c948f7-8dd6-5899-b4d4-0979e2020afd
Feed Name: The Record from Recorded Future News
ClearSky researchers identified a suspected Russian state-aligned espionage campaign targeting Ukraine that uses phishing emails with ZIP attachments containing a malicious Ukrainian-language document which installs the BadPaw loader and the MeowMeow backdoor; MeowMeow can read, write, and delete files and evades analysis by checking for virtual machines and common security tools. ClearSky attributes the activity with high confidence to a Russian state-aligned actor and with low confidence to APT28, and CERT‑UA separately reported a related campaign using ShadowSniff and SalatStealer.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
