APT28-Linked Campaign Deploys BadPaw Loader and MeowMeow Backdoor in Ukraine

Cybersecurity experts have revealed information on a recent Russian cyberattack that used the previously unidentified malware families BadPaw and MeowMeow to target Ukrainian organizations.

A phishing email with a link to a ZIP archive starts the attack chain. According to a research released this week by ClearSky, once extracted, an initial HTA file shows a lure document written in Ukrainian on border crossing requests to trick the victim.

The attack chain also results in the deployment of BadPaw, a.NET-based loader that communicates with a distant server to retrieve and launch MeowMeow, a sophisticated backdoor.

Based on the targeting footprint, the geopolitical nature of the lures utilized, and similarities to methods seen in earlier Russian cyber operations, the campaign has been moderately confidently linked read more about APT28-Linked Campaign Deploys BadPaw Loader and MeowMeow Backdoor in Ukraine.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *