logo

Russia-linked APT uses DRILLAPP backdoor to spy on Ukrainian targets

ID: ca37499e-5d76-521f-8f9c-040a4c4c2192

STIX ID: report--ca37499e-5d76-521f-8f9c-040a4c4c2192

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2026-03-16

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

A Russia-linked APT (attributed with low confidence to Laundry Bear / UAC-0190) conducted a February 2026 campaign against Ukrainian targets using a DRILLAPP backdoor delivered via malicious LNK and CPL lures. The backdoor runs Microsoft Edge/Chromium with relaxed security and remote-debugging enabled to access the file system, microphone, camera, and screen, and to download files via the Chrome DevTools Protocol, demonstrating an active, stealthy browser-based espionage capability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.