New malware BadPaw and MeowMeow used in Russian campaign against Ukraine
ClearSky has identified a targeted Russian campaign against Ukraine using two new malware families, BadPaw and MeowMeow. The attack begins with a phishing email linking to a ZIP archive. An HTA file displays a Ukrainian-language lure document about border crossing appeals, while the .NET loader BadPaw is downloaded in the background and, after contacting its command-and-control server, deploys the MeowMeow backdoor. Both are obfuscated with the .NET Reactor packer, run only dummy code unless launched with specific parameters, and MeowMeow terminates itself if it detects virtual machines or tools such as Wireshark, ProcMon and Fiddler. ClearSky attributes the campaign with high confidence to a Russian state-aligned actor and with low confidence to APT28.
What this means for your organisation
The campaign targets Ukraine, but the techniques are general. Malware that stays dormant until it is confident it is not being watched means the usual practice of sending a suspicious file for analysis returns a clean verdict. Norwegian organisations with operations, staff or suppliers in the region should consider themselves relevant targets, and everyone should note that a clean sandbox report is not sufficient grounds to close a case.
Berigo recommends
- Block HTA files and other scripting formats with little legitimate use, and prevent execution of content directly from ZIP archives.
- Build detection on endpoint behaviour and outbound traffic rather than relying on a file being analysable.
- Make sure incident handling has a route to escalate even when the sandbox says the file is harmless.
- Consider a dedicated threat assessment for units, staff and suppliers connected to Ukraine and the surrounding region.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch