Threat reportAPTTL-2026-0242
DRILLAPP/Laundry Bear — Ukraine Military Espionage via Microsoft Edge Chrome DevTools Protocol Abuse
DRILLAPP/Laundry Bear (TL-2026-0242), also tracked as Operation DRILLAPP, is a high-severity advanced persistent threat campaign, first published 2026-03-17. It is attributed to Void Blizzard (Russia) with low confidence, affects Microsoft Microsoft Edge, maps to 22 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 23 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 22MITRE ATT&CK
- Actors
- 1Void Blizzard
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 23Indicators of compromise
Key facts for TL-2026-0242
- Threat ID
- TL-2026-0242
- Also known as
- Operation DRILLAPP, DRILLAPP Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- Void Blizzard
- Attribution confidence
- LOW
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- military, government, judiciary, defense, education, transportation
- Target regions
- Ukraine, Eastern Europe, NATO Member States
- Detection rules
- 9
- Indicators of compromise
- 23
Malware and tooling in DRILLAPP/Laundry Bear
Malware and tooling: DRILLAPP, PLUGGYAPE, WebSocket over CDP (Chrome DevTools Protocol), javascript-obfuscator
How DRILLAPP/Laundry Bear works
Russia-linked APT group Laundry Bear (UAC-0190/Void Blizzard) deploys DRILLAPP, a JavaScript-based backdoor that abuses Microsoft Edge's Chrome DevTools Protocol (CDP) debugging interface for stealth surveillance and data exfiltration. The campaign targets Ukrainian military, judicial, and government organizations using charity-themed and judicial document lures delivered via LNK and CPL files.
DRILLAPP is a newly discovered JavaScript-based backdoor deployed by the Russia-linked APT group Laundry Bear (also tracked as UAC-0190 by CERT-UA and Void Blizzard by Microsoft). The campaign, observed throughout February 2026 and publicly disclosed by Lab52 (S2 Grupo) on March 13, 2026, represents a novel approach to cyber espionage that turns the victim's own web browser into a surveillance tool.
The attack chain begins with social engineering lures themed around Ukrainian charitable organizations (particularly Come Back Alive Foundation), Starlink terminal verification documents, weapons seizure reports, and Southern Office State Audit Service of Ukraine documents. Two distinct campaign variants have been identified:
**Variant 1 (Early February 2026):** Uses Windows shortcut (LNK) files that create an HTML Application (HTA) in the temporary folder. The HTA loads an obfuscated JavaScript payload hosted on pastefy.app (a legitimate paste service abused as a dead drop resolver). The LNK file is copied to the Windows Startup folder (%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup) for persistence.
**Variant 2 (Late February 2026):** Replaces LNK files with CPL (Windows Control Panel) modules, which function as DLL libraries. This variant includes enhanced backdoor capabilities including recursive file enumeration, batch file uploads, and arbitrary file downloads via the Chrome DevTools Protocol.
Both variants launch Microsoft Edge in headless mode with dangerous security-bypassing parameters: --no-sandbox, --disable-web-security, --allow-file-access-from-files, --use-fake-ui-for-media-stream, --auto-select-screen-capture-source=true, --disable-user-media-security, and --remote-debugging-port. These parameters grant the malware automatic access to the webcam, microphone, screen capture, and local filesystem without user interaction or consent prompts.
The core innovation of DRILLAPP is its abuse of the Chrome DevTools Protocol (CDP), an internal debugging protocol of Chromium-based browsers. Since JavaScript cannot natively download files from remote servers, the attackers use CDP (enabled via the --remote-debugging-port parameter on port 9222) to modify download folder paths and inject scripts that simulate user clicks, circumventing the browser's security restrictions on remote file operations.
DRILLAPP performs device fingerprinting using Canvas Fingerprinting combined with screen resolution and system language. The resulting hash is stored as a "stream_client_id" in browser storage and transmitted to the C2 along with the victim's detected country (determined via timezone analysis supporting UK, Russia, Germany, France, China, Japan, US, Brazil, India, Ukraine, Canada, Australia, Italy, Spain, and Poland time zones).
The C2 communication uses WebSocket protocol, with the WebSocket URL retrieved from pastefy.app paste entries. An early proof-of-concept sample uploaded from Russia on January 28, 2026 communicated with gnome.com, suggesting early development and testing.
Attribution to Laundry Bear is assessed at low-to-medium confidence based on overlapping tactics: use of charity-themed lures, hosting operational artifacts on public text-sharing services, and similarity to the PLUGGYAPE campaign reported by CERT-UA in January 2026 which targeted Ukrainian Armed Forces via Signal and WhatsApp. Lab52 notes that DRILLAPP appears to be in an early stage of development, indicating ongoing refinement of the tool.
MITRE ATT&CK techniques used in TL-2026-0242
collection
T1005 Data from Local System; T1113 Screen Capture; T1123 Audio Capture; T1125 Video Capture
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1059 Command and Scripting Interpreter; T1204 User Execution
command-and-control
T1071 Application Layer Protocol; T1102 Web Service; T1132 Data Encoding
discovery
T1082 System Information Discovery; T1083 File and Directory Discovery
persistence
T1547 Boot or Logon Autostart Execution
impact
initial-access
resource-development
T1583 Acquire Infrastructure; T1608 Stage Capabilities
reconnaissance
Affected products and versions in DRILLAPP/Laundry Bear
Remediation for DRILLAPP/Laundry Bear
Immediate actions
- Block known C2 IP addresses 80.89.224.13 and 188.137.228.162 at network perimeter
- Monitor and alert on Microsoft Edge processes launched with --remote-debugging-port or --no-sandbox flags
- Block or monitor outbound WebSocket connections to pastefy.app from non-developer endpoints
- Scan endpoints for LNK or CPL files in Startup folders that reference Edge with debugging parameters
- Deploy file hash IOCs to endpoint detection platforms
Workarounds
- Disable Chrome DevTools Protocol remote debugging via Group Policy (DisableDevTools)
- Restrict CPL file execution via AppLocker or WDAC policies
- Block LNK file execution from email attachments and downloads
Longer-term hardening
- Implement application control policies to prevent Edge from launching with unsafe flags (--disable-web-security, --no-sandbox)
- Deploy EDR with behavioral detection for browser abuse patterns (headless browser + camera/microphone access)
- Enforce network segmentation to limit lateral movement from compromised workstations
- Implement DNS sinkholing for known C2 domains
- Conduct user awareness training focused on charity-themed and government document phishing lures
- Enable browser policy controls to restrict Chrome DevTools Protocol remote debugging
Timeline of DRILLAPP/Laundry Bear
- Laundry Bear (Void Blizzard) first observed active, targeting NATO member states and Ukrainian institutions
- Dutch intelligence agencies AIVD/MIVD publicly unmask Laundry Bear as a Russian state-sponsored group; Microsoft designates as Void Blizzard
- PLUGGYAPE campaign against Ukrainian Armed Forces begins (October-December 2025), attributed to UAC-0190 by CERT-UA
- CERT-UA discloses UAC-0190/PLUGGYAPE attacks using Signal and WhatsApp to target Ukrainian defense forces
- Early DRILLAPP proof-of-concept sample uploaded from Russia, communicating with gnome.com for C2
- First DRILLAPP variant deployed using LNK files with charity-themed and Starlink verification lures
- Second DRILLAPP variant emerges using CPL files with enhanced capabilities including recursive file enumeration and batch uploads
- Lab52 (S2 Grupo) publicly discloses DRILLAPP backdoor with full technical analysis and IOCs
- The Hacker News, Security Affairs, The Record, and multiple outlets publish coverage of DRILLAPP campaign
- As of 2026-05-29, DRILLAPP remains ACTIVE: Russia-linked Laundry Bear/Void Blizzard (UAC-0190) is undisrupted and its Edge/CDP browser-as-C2 backdoor was assessed by Lab52 as in early development, implying ongoing refinement. No CVE exists (legitimate-feature abuse, so no patch path), no successor supersedes it, and no public reporting marks the Ukraine espionage campaign as concluded.
Sources cited for DRILLAPP/Laundry Bear
- Lab52 — DRILLAPP: New Backdoor Targeting Ukrainian Entities with Possible Links to Laundry Bear
- The Hacker News — DRILLAPP Backdoor Targets Ukraine, Abuses Microsoft Edge Debugging for Stealth Espionage
- Security Affairs — Russia-linked APT Uses DRILLAPP Backdoor to Spy on Ukrainian Targets
- The Record — Russia-linked Espionage Campaign Targeting Ukraine Using Starlink and Charity Lures
- ThousandGuards — DRILLAPP: When the Browser Becomes the Spy
- dev.ua — Russian Hackers Turned Microsoft Edge Into Covert Surveillance Tool
- CERT-UA — UAC-0190/PLUGGYAPE Advisory (Predecessor Campaign)
- Microsoft — Void Blizzard Targets Critical Sectors for Espionage
- The Record — Dutch Intelligence Unmasks Laundry Bear
- SOCPrime — UAC-0190 Uses PLUGGYAPE Against Ukrainian Armed Forces
Detection coverage for TL-2026-0242
As of 2026-03-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0242 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.