logo

DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear

ID: 6a9edeec-5f24-5bcd-b160-261c2e7423c2

STIX ID: report--6a9edeec-5f24-5bcd-b160-261c2e7423c2

Feed Name: Lab52 Blog

Threat Score
78/100

Date Published: 2026-03-13

Date Updated: 2026-04-28

Author: 3722304989

...
...

LAB52 at S2 Group observed a February 2026 campaign delivering a JavaScript-based backdoor called DRILLAPP that runs through the Edge browser. The malware leverages headless/remote-debugging browser flags and the Chrome DevTools Protocol to grant file system access and to capture microphone, camera, and screen content; two variants use LNK and CPL deployment methods. The report includes IOCs (file hashes, IPs, and Pastefy/short-link URLs) and attributes activity with low confidence to actors linked to Russia.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.