Theia

Article

Russian Cyberespionage Group Targets Ukraine with BadPaw and MeowMeow Malware Campaign

DEFENSE

Researchers identified a phishing campaign connected to a Russian cyberespionage group targeting Ukrainian organizations with two malware families: BadPaw and MeowMeow. The attack begins with a phishing email linking to a ZIP archive that, when opened, runs an HTA file displaying a lure about border crossing appeals.

This leads to the download of BadPaw, a .NET-based loader that communicates with a command-and-control server to install MeowMeow, a sophisticated backdoor. Both malware strains employ .NET Reactor for obfuscation and incorporate defense mechanisms such as environmental checks to detect analysis tools. The campaign is attributed to a Russia-linked threat actor with moderate confidence.

Russian Cyberespionage Group Targets Ukraine with BadPaw and MeowMeow Malware Campaign
Mar 7, 2026, 6:21 AM

No comments yet. Be the first to share your thoughts!