DRILLAPP: a new in-browser backdoor aimed at Ukrainian targets
Lab52 has identified a campaign against Ukrainian entities using a new JavaScript backdoor called DRILLAPP. The malware operates through the web browser and lets the attacker upload and download files and access the microphone, camera and screen. It is delivered through social engineering using judicial and charity-themed lures, runs as obfuscated scripts in a headless browser, and abuses built-in debugging flags and the Chrome DevTools Protocol to evade security controls.
What this means for your business
The browser is in practice an application platform, yet many organisations still treat it as a passive client. When an attacker runs inside the browser context, they inherit whatever the employee is already signed in to, plus the meeting room's microphone and camera. For Norwegian organisations with Ukraine-related activity, or staff who receive legal and humanitarian enquiries, this is a realistic scenario.
Berigo recommends
- Block or alert on browsers launched with debugging flags or in headless mode on client machines.
- Monitor unexpected outbound connections from browser processes and log use of the Chrome DevTools Protocol.
- Manage browser extensions and settings centrally through policy rather than by instructing individuals.
- Exercise a scenario where an employee has opened a document from an apparent legal enquiry, and clarify who decides to isolate the machine.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch