# DRILLAPP/Laundry Bear — Ukraine Military Espionage via Microsoft Edge Chrome DevTools Protocol Abuse

> Russia-linked APT group Laundry Bear (UAC-0190/Void Blizzard) deploys DRILLAPP, a JavaScript-based backdoor that abuses Microsoft Edge's Chrome DevTools Protocol (CDP) debugging interface for stealth surveillance and data exfiltration. The campaign targets Ukrainian military, judicial, and government organizations using charity-themed and judicial document lures delivered via LNK and CPL files.

- **Published:** 2026-03-17T12:00:00Z
- **Last reviewed:** 2026-03-17T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0242
- **ID:** TL-2026-0242
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** Void Blizzard (Russia)
- **Detections:** 9 · **IOCs:** 23 (full data via the Threadlinqs MCP server — Purple tier)

## Description

DRILLAPP is a newly discovered JavaScript-based backdoor deployed by the Russia-linked APT group Laundry Bear (also tracked as UAC-0190 by CERT-UA and Void Blizzard by Microsoft). The campaign, observed throughout February 2026 and publicly disclosed by Lab52 (S2 Grupo) on March 13, 2026, represents a novel approach to cyber espionage that turns the victim's own web browser into a surveillance tool.

The attack chain begins with social engineering lures themed around Ukrainian charitable organizations (particularly Come Back Alive Foundation), Starlink terminal verification documents, weapons seizure reports, and Southern Office State Audit Service of Ukraine documents. Two distinct campaign variants have been identified:

**Variant 1 (Early February 2026):** Uses Windows shortcut (LNK) files that create an HTML Application (HTA) in the temporary folder. The HTA loads an obfuscated JavaScript payload hosted on pastefy.app (a legitimate paste service abused as a dead drop resolver). The LNK file is copied to the Windows Startup folder (%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup) for persistence.

**Variant 2 (Late February 2026):** Replaces LNK files with CPL (Windows Control Panel) modules, which function as DLL libraries. This variant includes enhanced backdoor capabilities including recursive file enumeration, batch file uploads, and arbitrary file downloads via the Chrome DevTools Protocol.

Both variants launch Microsoft Edge in headless mode with dangerous security-bypassing parameters: --no-sandbox, --disable-web-security, --allow-file-access-from-files, --use-fake-ui-for-media-stream, --auto-select-screen-capture-source=true, --disable-user-media-security, and --remote-debugging-port. These parameters grant the malware automatic access to the webcam, microphone, screen capture, and local filesystem without user interaction or consent prompts.

The core innovation of DRILLAPP is its abuse of the Chrome DevTools Protocol (CDP), an internal debugging protocol of Chromium-based browsers. Since JavaScript cannot natively download files from remote servers, the attackers use CDP (enabled via the --remote-debugging-port parameter on port 9222) to modify download folder paths and inject scripts that simulate user clicks, circumventing the browser's security restrictions on remote file operations.

DRILLAPP performs device fingerprinting using Canvas Fingerprinting combined with screen resolution and system language. The resulting hash is stored as a "stream_client_id" in browser storage and transmitted to the C2 along with the victim's detected country (determined via timezone analysis supporting UK, Russia, Germany, France, China, Japan, US, Brazil, India, Ukraine, Canada, Australia, Italy, Spain, and Poland time zones).

The C2 communication uses WebSocket protocol, with the WebSocket URL retrieved from pastefy.app paste entries. An early proof-of-concept sample uploaded from Russia on January 28, 2026 communicated with gnome.com, suggesting early development and testing.

Attribution to Laundry Bear is assessed at low-to-medium confidence based on overlapping tactics: use of charity-themed lures, hosting operational artifacts on public text-sharing services, and similarity to the PLUGGYAPE campaign reported by CERT-UA in January 2026 which targeted Ukrainian Armed Forces via Signal and WhatsApp. Lab52 notes that DRILLAPP appears to be in an early stage of development, indicating ongoing refinement of the tool.

## MITRE ATT&CK

- T1598 Phishing for Information
- T1608 Stage Capabilities
- T1583 Acquire Infrastructure
- T1566 Phishing
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1547 Boot or Logon Autostart Execution
- T1218 System Binary Proxy Execution
- T1140 Deobfuscate/Decode Files or Information
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1083 File and Directory Discovery
- T1082 System Information Discovery
- T1005 Data from Local System
- T1113 Screen Capture
- T1123 Audio Capture
- T1125 Video Capture
- T1071 Application Layer Protocol
- T1102 Web Service
- T1132 Data Encoding
- T1041 Exfiltration Over C2 Channel
- T1565 Data Manipulation

## Sources

- [Lab52 — DRILLAPP: New Backdoor Targeting Ukrainian Entities with Possible Links to Laundry Bear](https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/)
- [The Hacker News — DRILLAPP Backdoor Targets Ukraine, Abuses Microsoft Edge Debugging for Stealth Espionage](https://thehackernews.com/2026/03/drillapp-backdoor-targets-ukraine.html)
- [Security Affairs — Russia-linked APT Uses DRILLAPP Backdoor to Spy on Ukrainian Targets](https://securityaffairs.com/189519/malware/russia-linked-apt-uses-drillapp-backdoor-to-spy-on-ukrainian-targets.html)
- [The Record — Russia-linked Espionage Campaign Targeting Ukraine Using Starlink and Charity Lures](https://therecord.media/russia-ukraine-cyber-espionage-group)
- [ThousandGuards — DRILLAPP: When the Browser Becomes the Spy](https://www.thousandguards.com/post/drillapp-when-the-browser-becomes-the-spy)
- [dev.ua — Russian Hackers Turned Microsoft Edge Into Covert Surveillance Tool](https://dev.ua/en/news/rosiiski-khakery-atakuiut-ukrainu-cherez-microsoft-edge-1773671273)
- [CERT-UA — UAC-0190/PLUGGYAPE Advisory (Predecessor Campaign)](https://securityaffairs.com/186910/intelligence/cert-ua-reports-pluggyape-cyberattacks-on-defense-forces.html)
- [Microsoft — Void Blizzard Targets Critical Sectors for Espionage](https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/)
- [The Record — Dutch Intelligence Unmasks Laundry Bear](https://therecord.media/laundry-bear-void-blizzard-russia-hackers-netherlands)
- [SOCPrime — UAC-0190 Uses PLUGGYAPE Against Ukrainian Armed Forces](https://socprime.com/blog/uac-0190-attacks-detection/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0242
