Russian hackers deploy new malware in phishing campaign targeting Ukraine

Russian hackers deploy new malware in phishing campaign targeting Ukraine

Researchers report a suspected Russian espionage campaign targeting Ukraine that starts with a phishing email containing a ZIP archive and a malicious Ukrainian-language document, which triggers a loader called BadPaw and installs a backdoor named MeowMeow. The MeowMeow backdoor enables file access and manipulation, includes anti-analysis checks that terminate execution in virtual machines or sandboxes, and ClearSky attributes the operation with high confidence to a Russian state-aligned actor and with low confidence to APT28. #BadPaw #MeowMeow

Keypoints

  • The campaign uses a phishing lure with a ZIP archive containing a Ukrainian-language permit document.
  • Opening the archive downloads the BadPaw loader, which deploys the MeowMeow backdoor.
  • MeowMeow can check for specific files and read, write, or delete data on infected machines.
  • Both malware strains employ anti-detection techniques; MeowMeow self-terminates if it detects VMs or security tools.
  • ClearSky attributes the campaign to a Russian state-aligned actor, with low-confidence links to APT28; CERT-UA separately reported ShadowSniff and SalatStealer activity by UAC-0252.

Read More: https://therecord.media/russian-ukraine-hackers-malware