APT28 (Fancy Bear) Deploys BadPaw Loader and MeowMeow Backdoor Targeting Ukrainian Critical Infrastructure

APT28 (Fancy Bear) Deploys BadPaw Loader and MeowMeow (TL-2026-0188), also tracked as Operation MeowMeow, is a high-severity advanced persistent threat campaign, first published 2026-03-06. It is attributed to APT28 (Russia) with medium confidence, affects Microsoft Windows, maps to 18 MITRE ATT&CK techniques (T1005, T1012, T1027), and is covered by 9 detection rules and 18 indicators of compromise.

Key facts for TL-2026-0188

Threat ID
TL-2026-0188
Also known as
Operation MeowMeow, BadPaw Campaign
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-03-06
Last reviewed
2026-03-06
Attribution
APT28
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
government, defense, critical-infrastructure, energy, transportation
Target regions
Ukraine, Eastern Europe
Detection rules
9
Indicators of compromise
18

Malware and tooling in APT28 (Fancy Bear) Deploys BadPaw Loader and MeowMeow

Malware and tooling: BadPaw, MeowMeow, .NET Reactor, Custom HTTP C2 (BadPaw/MeowMeow)

ClearSky researchers identified APT28 (Fancy Bear / GRU Unit 26165) deploying two previously undocumented malware strains — BadPaw (.NET loader) and MeowMeow (modular backdoor) — against Ukrainian government and critical infrastructure targets via spearphishing campaigns using macro-enabled documents disguised as Ukrainian border crossing appeals.

How APT28 (Fancy Bear) Deploys BadPaw Loader and MeowMeow works

APT28, the Russian state-sponsored threat actor linked to GRU Unit 26165, has been observed deploying two previously undocumented malware families — BadPaw and MeowMeow — in a targeted campaign against Ukrainian government entities and critical infrastructure organizations.

The attack chain begins with spearphishing emails sent from compromised ukr.net accounts to establish credibility with Ukrainian targets. The emails contain links purporting to host ZIP archives. When a victim clicks the link, they are first redirected to an attacker-controlled domain that loads a tracking pixel (an exceptionally small image) to signal the operators that the link was accessed. A second redirect then delivers the actual ZIP archive.

The ZIP archive contains a disguised HTA (HTML Application) file masquerading as an HTML document. Upon execution, the HTA displays a Ukrainian-language decoy document — a confirmation of receipt for a government appeal regarding a Ukrainian border crossing — while simultaneously executing malicious code in the background.

The HTA file performs sandbox evasion by querying the Windows Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallDate to determine the OS installation date. If the system is less than 10 days old, execution is aborted, effectively evading freshly provisioned analysis sandboxes. The malware also monitors for the presence of forensic and analysis tools including Wireshark, Procmon (Process Monitor), Ollydbg, and Fiddler — terminating execution if any are detected.

A scheduled task is then created that executes a VBScript component. This VBScript uses steganographic techniques to extract an executable payload embedded within a PNG image file. The extracted payload is the BadPaw loader.

BadPaw is a .NET-based loader heavily obfuscated with .NET Reactor, a commercial protection tool for .NET assemblies. BadPaw requires a specific runtime parameter ("-v") to activate — without this parameter, BadPaw displays a benign decoy GUI with a cat image and the text "Meow Meow Meow," appearing as a harmless application. When properly activated, BadPaw establishes communication with its command-and-control server through staged endpoints: first retrieving a numeric response from the /getcalendar endpoint, then accessing a landing page titled "Telemetry UP!" via /eventmanager, and finally downloading ASCII-encoded payload data embedded within HTML responses.

The final payload is MeowMeow, a sophisticated backdoor with modular plugin architecture. MeowMeow implements four defensive layers: runtime parameter validation, .NET Reactor obfuscation, sandbox detection via OS install date checks, and active monitoring for forensic tools. Once operational, MeowMeow provides remote PowerShell command execution on the compromised host and full file system operations including read, write, and delete capabilities. Russian-language strings were identified in the MeowMeow source code, described as a potential OPSEC failure indicating a Russian-speaking developer.

At the time of ClearSky's analysis, only 9 out of tested antivirus engines detected the payload, indicating effective evasion of signature-based detection. ClearSky attributes the campaign with high confidence to a Russian state-aligned threat actor and with low-to-moderate confidence specifically to APT28 (Fancy Bear), based on the Ukrainian targeting footprint, geopolitical nature of lures, Russian-language code artifacts, and tactical overlaps with previously documented Russian cyber operations.

---

**Revalidated on 2026-03-12**

The APT28 BadPaw/MeowMeow campaign remains a confirmed active threat as of March 2026, representing one component of APT28's most aggressive operational surge against Ukraine and Eastern Europe in the conflict era. ClearSky's March 4, 2026 disclosure revealed a sophisticated multi-stage phishing chain: emails from ukr.net addresses deliver ZIP archives containing HTA files with Ukrainian border-crossing appeal lures, which execute sandbox evasion checks (Windows Registry InstallDate threshold of 10 days), establish persistence via scheduled tasks and VBScript, and use steganography to extract the BadPaw .NET loader from PNG images. BadPaw then deploys MeowMeow, a backdoor requiring the '-v' parameter for activation, protected by .NET Reactor obfuscation, and equipped with anti-analysis scanning for Wireshark, Procmon, Ollydbg, and Fiddler. MeowMeow provides remote PowerShell command execution and full file system operations (read/write/delete). Russian language strings in the source code reinforce attribution.

This campaign is contextualized by a dramatic escalation of APT28 operations between May 2025 and March 2026. In January 2026, Operation Neusploit (documented by Trellix and Zscaler) weaponized CVE-2026-21509 within 24 hours of Microsoft's disclosure, launching a 72-hour spear-phishing blitz across 9 nations with NotDoor Outlook VBA backdoor and modified Covenant implants using Filen cloud C2. CERT-UA advisory #19542 confirmed this activity against Ukrainian state bodies. ESET's 'Sednit Reloaded' report (March 10, 2026) exposed BeardShell and Covenant paired implants conducting Ukrainian military surveillance since April 2024, with code lineage traced to APT28's 2010-era XTunnel and XAgent tools. The July 2025 LAMEHUG discovery marked the first documented malware integrating an LLM for command generation. UK sanctions against 3 GRU units and 18 officers in July 2025, alongside the 21-agency CISA joint advisory AA25-141A in May 2025, underscore the international recognition of APT28's intensified targeting of Ukraine and its Western support infrastructure. Organizations in scope should prioritize detection of .NET Reactor-obfuscated loaders, steganographic payload delivery from PNG files, scheduled task persistence, anti-forensic environment checks, and cloud-based C2 communication patterns.

MITRE ATT&CK techniques used in TL-2026-0188

collection

T1005 Data from Local System

discovery

T1012 Query Registry; T1082 System Information Discovery; T1083 File and Directory Discovery; T1518 Software Discovery

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1497 Virtualization/Sandbox Evasion

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1204 User Execution

command-and-control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1132 Data Encoding

initial-access

T1566 Phishing

Affected products and versions in APT28 (Fancy Bear) Deploys BadPaw Loader and MeowMeow

  • Microsoft — Windows
    Vulnerable versions: 10; 11; Server 2016; Server 2019; Server 2022
  • Microsoft — .NET Framework
    Vulnerable versions: 4.x

Remediation for APT28 (Fancy Bear) Deploys BadPaw Loader and MeowMeow

Immediate actions

  • Block emails from unknown ukr.net senders at the mail gateway
  • Block HTA file execution via Group Policy (disable mshta.exe)
  • Deploy detection rules for .NET Reactor-obfuscated binaries
  • Monitor for scheduled tasks creating VBScript execution chains
  • Hunt for /getcalendar and /eventmanager HTTP request patterns in proxy logs
  • Block execution of unsigned .NET assemblies from user-writable directories

Workarounds

  • Disable Windows Script Host (WSH) execution via registry
  • Block mshta.exe execution via Windows Defender Application Control
  • Restrict PowerShell to ConstrainedLanguage mode on endpoints
  • Enable attack surface reduction rules for Office macro execution

Longer-term hardening

  • Deploy EDR with behavioral detection for steganographic payload extraction
  • Implement application whitelisting to prevent unauthorized .NET execution
  • Enable PowerShell Constrained Language Mode and script block logging
  • Segment critical infrastructure networks from general user networks
  • Implement DMARC/DKIM/SPF for all organizational email domains
  • Deploy network monitoring for anomalous HTTP beacon patterns

Weaknesses (CWE) in APT28 (Fancy Bear) Deploys BadPaw Loader and MeowMeow

CWE-506, CWE-451

Timeline of APT28 (Fancy Bear) Deploys BadPaw Loader and MeowMeow

  • CISA joint advisory AA25-141A issued by 21 agencies across 11 nations documenting APT28 (GRU Unit 26165) two-year campaign targeting Western logistics and technology companies coordinating Ukraine aid, including compromise of border crossing cameras and network-edge devices [Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-141a]
  • CERT-UA publicly documents SlimAgent keylogger deployed by APT28 against Ukrainian government systems, capable of keystroke capture, screenshot collection, and clipboard data harvesting with AES/RSA encryption [Source: https://securityaffairs.com/189230/apt/apt28-conducts-long-term-espionage-on-ukrainian-forces-using-custom-malware.html]
  • CERT-UA discovers LAMEHUG malware attributed to APT28 — first publicly documented malware integrating an LLM (Qwen2.5-Coder-32B-Instruct via HuggingFace) to dynamically generate attack commands, targeting Ukrainian security and defense sector [Source: https://thehackernews.com/2025/07/cert-ua-discovers-lamehug-malware.html]
  • UK NCSC attributes Authentic Antics credential-stealing malware to GRU/APT28; UK Government sanctions three GRU units (26165, 29155, 74455) and 18 GRU officers for global cyber and information interference operations [Source: https://www.ncsc.gov.uk/news/uk-call-out-russian-military-intelligence-use-espionage-tool]
  • Microsoft discloses CVE-2026-21509 (CVSS 7.8), a critical Microsoft Office OLE security bypass vulnerability allowing automatic remote content download without user interaction; APT28 weaponizes it within 24 hours [Source: https://thehackernews.com/2026/02/apt28-uses-microsoft-office-cve-2026.html]
  • APT28 launches Operation Neusploit — 72-hour spear-phishing campaign (Jan 28-30) delivering 29+ emails across 9 Eastern European nations targeting defense ministries (40%), transport/logistics (35%), and diplomatic entities (25%), exploiting CVE-2026-21509 [Source: https://www.trellix.com/blogs/research/apt28-stealthy-campaign-leveraging-cve-2026-21509-cloud-c2/]
  • CERT-UA issues advisory #19542 warning of UAC-0001 (APT28) targeting Ukrainian state bodies with malicious Office documents exploiting CVE-2026-21509, deploying Covenant framework via COM hijacking and Filen cloud C2 [Source: https://socprime.com/blog/detect-uac-0001-attacks-exploiting-cve-2026-21509/]
  • Zscaler ThreatLabz publishes Operation Neusploit analysis identifying MiniDoor (simplified NotDoor variant), PixyNetLoader, and Covenant Grunt deployment with server-side geofencing evasion techniques limiting payload delivery to targeted regions [Source: https://www.zscaler.com/blogs/security-research/apt28-leverages-cve-2026-21509-operation-neusploit]
  • Trellix publishes detailed analysis of Operation Neusploit revealing NotDoor Outlook VBA backdoor, CovenantGrunt implant, SimpleLoader, and EhStoreShell steganography loader with IOCs including C2 domains and malware hashes [Source: https://www.trellix.com/blogs/research/apt28-stealthy-campaign-leveraging-cve-2026-21509-cloud-c2/]
  • Earliest estimated start of APT28 spearphishing campaign targeting Ukrainian government entities with BadPaw/MeowMeow malware
  • Spearphishing emails observed being sent from compromised ukr.net accounts to Ukrainian government targets with border crossing appeal lures
  • ClearSky researchers begin analysis of recovered BadPaw loader and MeowMeow backdoor samples
  • ClearSky publishes report ''Exposing a Russian Campaign Targeting Ukraine Using New Malware Duo: BadPaw and MeowMeow'' — disclosing .NET-based BadPaw loader using PNG steganography and MeowMeow backdoor with PowerShell execution, anti-sandbox checks, and .NET Reactor obfuscation [Source: https://www.clearskysec.com/russian-campaign-targeting-ukraine-badpaw-and-meowmeow/]
  • ClearSky publishes research report 'Exposing a Russian Campaign Targeting Ukraine Using New Malware Duo: BadPaw and MeowMeow' with full technical analysis
  • ClearSky attributes campaign with high confidence to Russian state actor and low-to-moderate confidence specifically to APT28 based on targeting, lures, and code artifacts
  • Widespread security media coverage by The Hacker News, Security Affairs, Infosecurity Magazine, The Record, and Industrial Cyber
  • Campaign remains active with low AV detection rate (9 engines); threat intelligence community monitoring for additional infrastructure and samples
  • ESET publishes ''Sednit Reloaded: Back in the Trenches'' revealing APT28''s BeardShell and Covenant paired implants used for long-term Ukrainian military surveillance since April 2024, with code continuity traced back to 2010-era XTunnel and XAgent tools [Source: https://securityaffairs.com/189230/apt/apt28-conducts-long-term-espionage-on-ukrainian-forces-using-custom-malware.html]
  • As of 2026-05-29, this APT28/GRU Unit 26165 BadPaw-loader and MeowMeow-backdoor campaign against Ukraine remains ACTIVE; it was disclosed by ClearSky in March 2026 and the macro/phishing-based intrusion set has no CVE to patch. APT28 is undisrupted, with CERT-UA confirming continued Ukraine operations (Feb 2026 alerts, Mar-Apr 2026 healthcare/government targeting).

Sources cited for APT28 (Fancy Bear) Deploys BadPaw Loader and MeowMeow

Threats related to APT28 (Fancy Bear) Deploys BadPaw Loader and MeowMeow

Detection coverage for TL-2026-0188

As of 2026-03-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0188 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats