Multi-Stage "BadPaw" Malware Campaign Targets Ukraine
ID: 53bf08f8-3dcd-54b7-8e01-0bd40b14e386
STIX ID: report--53bf08f8-3dcd-54b7-8e01-0bd40b14e386
Feed Name: Infosecurity Magazine (News)
ClearSky researchers uncovered a targeted malware campaign (BadPaw) leveraging ukr.net email credibility and staged redirects to deliver an HTA disguised as an HTML file; the payload performs sandbox checks, extracts components from ZIP archives, achieves persistence via a scheduled task that uses steganography to load executables, and deploys a multi-layered MeowMeow backdoor with runtime checks, obfuscation and forensic-tool detection — artifacts include C2 endpoints, file names and Russian-language strings suggesting possible Russian-origin activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
