logo

Weaponized Browsers: How the ‘DRILLAPP’ Backdoor Turns Microsoft Edge into an Espionage Tool

ID: 68b53d6c-a67d-521b-b00e-ef1dcbe950e3

STIX ID: report--68b53d6c-a67d-521b-b00e-ef1dcbe950e3

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-03-17

Date Updated: 2026-04-23

Author: Ddos

...
...

LAB52 uncovered an active February 2026 campaign against Ukrainian targets that abuses Microsoft Edge debugging parameters to run a JavaScript backdoor called DRILLAPP. Delivered via social-engineered LNK shortcuts and scripts hosted on public paste sites, DRILLAPP enables file upload/download, microphone and webcam access, and screen recording; researchers note low-confidence overlaps with Laundry Bear and provide defensive recommendations including monitoring unusual browser launch arguments, restricting LNK files, and auditing browser permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.