APT28 Hits Ukraine with New BadPaw Loader and MeowMeow Backdoor
Mar 5, 2026 // 14:58 - Lina Schonbein


Cybersecurity researchers have identified a new campaign by the Russian state-sponsored threat group APT28 (also known as Fancy Bear or Forest Blizzard) targeting Ukrainian entities with two previously undocumented malware families: BadPaw and MeowMeow.

Attack Chain and Lure

According to ClearSky Cyber Security, the campaign utilizes a multi-stage process:

  • Initial Access: Phishing emails, appearing to come from ukr[.]net, target Ukrainian users.
  • Payload Delivery: A link in the email downloads a ZIP file, which, when executed via an HTA file, displays a bogus “border crossing appeal” document, researchers note.
  • Tracking: The infection chain includes a redirect step that loads a tracking pixel to monitor victim interaction.

Malware Analysis

The campaign employs two newly identified tools for operational control: 

  • BadPaw: A .NET-based loader designed to fetch additional payloads from a command-and-control (C2) server.
  • MeowMeow: A backdoor designed for file management and remote command execution.

#and  #apt28  #backdoor  #badpaw  #hits  #loader  #meowmeow  #new  #news  #ukraine  #with   —   News