logo

Russian APT targets Ukraine with BadPaw and MeowMeow malware

ID: fe37c388-3f8c-58eb-baa0-985827c17275

STIX ID: report--fe37c388-3f8c-58eb-baa0-985827c17275

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-03-05

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Researchers uncovered a Russia-linked phishing campaign targeting Ukrainian entities that uses ZIP-delivered HTA lures to deploy a .NET loader called BadPaw and a backdoor named MeowMeow; the malware chain employs steganography, scheduled-task persistence, anti-analysis checks (e.g., InstallDate and VM/tool detection), and .NET Reactor packing, and is attributed with moderate confidence to APT28.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.