DRILLAPP/Laundry Bear — Ukraine Military Espionage via Microsoft Edge Chrome DevTools Protocol Abuse — Threadlinqs Intelligence
As of 2026-05-30, DRILLAPP/Laundry Bear — Ukraine Military Espionage via Microsoft Edge Chrome DevTools Protocol Abuse is a high-severity apt threat attributed to Void Blizzard (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-0242 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: Void Blizzard · Russia · ESPIONAGE
Russia-linked APT group Laundry Bear (UAC-0190/Void Blizzard) deploys DRILLAPP, a JavaScript-based backdoor that abuses Microsoft Edge's Chrome DevTools Protocol (CDP) debugging interface for stealth
DRILLAPP is a newly discovered JavaScript-based backdoor deployed by the Russia-linked APT group Laundry Bear (also tracked as UAC-0190 by CERT-UA and Void Blizzard by Microsoft). The campaign, observed throughout February 2026 and publicly disclosed by Lab52 (S2 Grupo) on March 13, 2026, represents a novel approach to cyber espionage that turns the victim's own web browser into a surveillance tool.
The attack chain begins with social engineering lures themed around Ukrainian charitable organizations (particularly Come Back Alive Foundation), Starlink terminal verification documents, weapons seizure reports, and Southern Office State Audit Service of Ukraine documents. Two distinct campaign variants have been identified:
**Variant 1 (Early February 2026):** Uses Windows shortcut (LNK) files that create an HTML Application (HTA) in the temporary folder. The HTA loads an obfuscated JavaScript payload hosted on pastefy.app (a legitimate paste service abused as a dead drop resolver). The LNK file is copied to the Windows Startup folder (%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup) for persistence.
**Variant 2 (Late February 2026):** Replaces LNK files with CPL (Windows Control Panel) modules, which function as DLL libraries. This variant includes enhanced backdoor capabilities including recursive file enumeration, batch file uploads, and arbitrary file downloads via the Chrome DevTools Protocol.
Both variants launch Microsoft Edge in headless mode with dangerous security-bypassing parameters: --no-sandbox, --disable-web-security, --allow-file-access-from-files, --use-fake-ui-for-media-stream, --auto-select-screen-capture-source=true, --disable-user-media-security, and --remote-debugging-port. These parameters grant the malware automatic access to the webcam, microphone, screen capture, and local filesystem without user interaction or consent prompts.
The core innovation of DRILLAPP is its abuse of the Chrome DevTools Protocol (CDP), an internal debugging protocol of Chromium-based browsers. Since JavaScript cannot natively download files from remote servers, the attackers use CDP (enabled via the --remote-debugging-port parameter on port 9222) to modify download folder paths and inject scripts that simulate user clicks, circumventing the browser's security restrictions on remote file operations.
DRILLAPP performs device fingerprinting using Canvas Fingerprinting combined with screen resolution and system language. The resulting hash is stored as a "stream_client_id" in browser storage and transmitted to the C2 along with the victim's detected country (determined via timezone analysis supporting UK, Russia, Germany, France, China, Japan, US, Brazil, India, Ukraine, Canada, Australia, Italy, Spain, and Poland time zones).
The C2 communication uses WebSocket protocol, with the WebSocket URL retrieved from pastefy.app paste entries. An early proof-of-concept sample uploaded from Russia on January 28, 2026 communicated with gnome.com, suggesting early development and testing.
Attribution to Laundry Bear is assessed at low-to-medium confidence based on overlapping tactics: use of charity-themed lures, hosting operational artifacts on public text-sharing services, and similarity to the PLUGGYAPE campaign reported by CERT-UA in January 2026 which targeted Ukrainian Armed Forces via Signal and WhatsApp. Lab52 notes that DRILLAPP appears to be in an early stage of development, indicating ongoing refinement of the tool.
Target sectors: military, government, judiciary, defense, education, transportation
Target regions: Ukraine, Eastern Europe, NATO Member States
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1598, T1608, T1583, T1566, T1204, T1059, T1547, T1218, T1140, T1036