Weaponized Browsers: How the ‘DRILLAPP’ Backdoor Turns Microsoft Edge into an Espionage Tool
ID: 68b53d6c-a67d-521b-b00e-ef1dcbe950e3
STIX ID: report--68b53d6c-a67d-521b-b00e-ef1dcbe950e3
Feed Name: securityonline.info
LAB52 uncovered an active February 2026 campaign against Ukrainian targets that abuses Microsoft Edge debugging parameters to run a JavaScript backdoor called DRILLAPP. Delivered via social-engineered LNK shortcuts and scripts hosted on public paste sites, DRILLAPP enables file upload/download, microphone and webcam access, and screen recording; researchers note low-confidence overlaps with Laundry Bear and provide defensive recommendations including monitoring unusual browser launch arguments, restricting LNK files, and auditing browser permissions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
