APT28 (Fancy Bear) Deploys BadPaw Loader and MeowMeow Backdoor Targeting Ukrainian Critical Infrastructure — Threadlinqs Intelligence
As of 2026-05-30, APT28 (Fancy Bear) Deploys BadPaw Loader and MeowMeow Backdoor Targeting Ukrainian Critical Infrastructure is a high-severity apt threat attributed to APT28 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-0188 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: APT28 · Russia · ESPIONAGE
ClearSky researchers identified APT28 (Fancy Bear / GRU Unit 26165) deploying two previously undocumented malware strains — BadPaw (.NET loader) and MeowMeow (modular backdoor) — against Ukrainian
APT28, the Russian state-sponsored threat actor linked to GRU Unit 26165, has been observed deploying two previously undocumented malware families — BadPaw and MeowMeow — in a targeted campaign against Ukrainian government entities and critical infrastructure organizations.
The attack chain begins with spearphishing emails sent from compromised ukr.net accounts to establish credibility with Ukrainian targets. The emails contain links purporting to host ZIP archives. When a victim clicks the link, they are first redirected to an attacker-controlled domain that loads a tracking pixel (an exceptionally small image) to signal the operators that the link was accessed. A second redirect then delivers the actual ZIP archive.
The ZIP archive contains a disguised HTA (HTML Application) file masquerading as an HTML document. Upon execution, the HTA displays a Ukrainian-language decoy document — a confirmation of receipt for a government appeal regarding a Ukrainian border crossing — while simultaneously executing malicious code in the background.
The HTA file performs sandbox evasion by querying the Windows Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallDate to determine the OS installation date. If the system is less than 10 days old, execution is aborted, effectively evading freshly provisioned analysis sandboxes. The malware also monitors for the presence of forensic and analysis tools including Wireshark, Procmon (Process Monitor), Ollydbg, and Fiddler — terminating execution if any are detected.
A scheduled task is then created that executes a VBScript component. This VBScript uses steganographic techniques to extract an executable payload embedded within a PNG image file. The extracted payload is the BadPaw loader.
BadPaw is a .NET-based loader heavily obfuscated with .NET Reactor, a commercial protection tool for .NET assemblies. BadPaw requires a specific runtime parameter ("-v") to activate — without this parameter, BadPaw displays a benign decoy GUI with a cat image and the text "Meow Meow Meow," appearing as a harmless application. When properly activated, BadPaw establishes communication with its command-and-control server through staged endpoints: first retrieving a numeric response from the /getcalendar endpoint, then accessing a landing page titled "Telemetry UP!" via /eventmanager, and finally downloading ASCII-encoded payload data embedded within HTML responses.
The final payload is MeowMeow, a sophisticated backdoor with modular plugin architecture. MeowMeow implements four defensive layers: runtime parameter validation, .NET Reactor obfuscation, sandbox detection via OS install date checks, and active monitoring for forensic tools. Once operational, MeowMeow provides remote PowerShell command execution on the compromised host and full file system operations including read, write, and delete capabilities. Russian-language strings were identified in the MeowMeow source code, described as a potential OPSEC failure indicating a Russian-speaking developer.
At the time of ClearSky's analysis, only 9 out of tested antivirus engines detected the payload, indicating effective evasion of signature-based detection. ClearSky attributes the campaign with high confidence to a Russian state-aligned threat actor and with low-to-moderate confidence specifically to APT28 (Fancy Bear), based on the Ukrainian targeting footprint, geopolitical nature of lures, Russian-language code artifacts, and tactical overlaps with previously documented Russian cyber operations.
---
**Revalidated on 2026-03-12**
The APT28 BadPaw/MeowMeow campaign remains a confirmed active threat as of March 2026, representing one component of APT28's most aggressive operational surge against Ukraine and Eastern Europe in the conflict era. ClearSky's March 4, 2026 disclosure revealed a sophisticated multi-stage phishing chain: emails from ukr.net addresses deliver ZIP archives containing HTA files with Ukrainian border-crossing appeal
Weaknesses (CWE)
CWE-506, CWE-451
Target sectors: government, defense, critical-infrastructure, energy, transportation
Target regions: Ukraine, Eastern Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1566, T1204, T1059, T1059, T1053, T1053, T1027, T1027, T1140, T1497