logo

APT28-Linked Campaign Deploys BadPaw Loader and MeowMeow Backdoor in Ukraine

ID: 8accf94f-27d5-5d06-a7f1-f3bb49cd7084

STIX ID: report--8accf94f-27d5-5d06-a7f1-f3bb49cd7084

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-03-05

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

ClearSky researchers report a Russian-state-aligned cyber espionage campaign targeting Ukrainian organizations that deploys two novel malware families: BadPaw, a .NET-based loader embedded via a PNG and VBScript extraction chain, and MeowMeow, a backdoor capable of remote PowerShell execution and file operations. The attack begins with a phishing email linking to a ZIP containing an HTA that drops a decoy document, performs sandbox and environment checks, installs a scheduled task for persistence, and fetches additional components from a C2; the malware includes anti-analysis checks and decoy GUI behaviors. The activity is attributed with moderate confidence to APT28 based on targeting, geopolitical lures, and overlaps with previously observed techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.