BadPaw and MeowMeow: Russian Cyber Offensive Targets Ukraine with Novel Malware Duo
ID: b670dc60-cbb5-557f-8f09-239c437b1ddc
STIX ID: report--b670dc60-cbb5-557f-8f09-239c437b1ddc
Feed Name: securityonline.info
Threat Score
ClearSky reports a targeted Russian state-aligned campaign against Ukraine that uses phishing ZIPs containing HTA files and steganography (hidden data in CAT.png) to deploy BadPaw (a .NET loader) which fetches the MeowMeow backdoor from C2 virtualdailyplanner.pro; both components employ functional decoys and anti-analysis checks, and Russian-language strings in the code support attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
