Russia-linked APT uses DRILLAPP backdoor to spy on Ukrainian targets
ID: ca37499e-5d76-521f-8f9c-040a4c4c2192
STIX ID: report--ca37499e-5d76-521f-8f9c-040a4c4c2192
Feed Name: Security Affairs
A Russia-linked APT (attributed with low confidence to Laundry Bear / UAC-0190) conducted a February 2026 campaign against Ukrainian targets using a DRILLAPP backdoor delivered via malicious LNK and CPL lures. The backdoor runs Microsoft Edge/Chromium with relaxed security and remote-debugging enabled to access the file system, microphone, camera, and screen, and to download files via the Chrome DevTools Protocol, demonstrating an active, stealthy browser-based espionage capability.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
