logo

DRILLAPP Backdoor Targets Ukraine, Abuses Microsoft Edge Debugging for Stealth Espionage

ID: 2c87aa17-3acd-52e4-8da1-62602114a046

STIX ID: report--2c87aa17-3acd-52e4-8da1-62602114a046

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-03-16

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

S2 Grupo LAB52 reported a February 2026 campaign, dubbed DRILLAPP, targeting Ukrainian entities with a JavaScript backdoor that runs through Microsoft Edge (Chromium) in headless mode to exfiltrate files and capture audio/video/screens. The attackers delivered the loader via Windows shortcut/HTA or Control Panel module lures, used Pastefy/other domains as dead‑drop resolvers for C2, leveraged Chrome DevTools Protocol to bypass browser download restrictions, and exhibited functionality for persistence, recursive file enumeration, and device fingerprinting; overlaps with the Laundry Bear/PLUGGYAPE activity suggest a likely Russia‑linked actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.