Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareUsed by 1 actor

MeowMeow

MeowMeow is a previously undocumented backdoor reported by ClearSky as part of a Russia-linked phishing campaign targeting Ukrainian organizations and entities. In the observed intrusion chain, victims received phishing emails, including messages sent from ukr[.]net-hosted addresses, that linked to a ZIP archive containing a Ukrainian-language lure related to border-crossing permits or appeals. The archive launched an HTA-based infection chain that ultimately delivered the .NET-based BadPaw loader, which established command-and-control communications and then deployed MeowMeow.

MeowMeow is described as a sophisticated backdoor used for cyberespionage. Reported capabilities include access to infected systems, remote execution of PowerShell commands, file enumeration, checking whether specific files exist, and reading, writing, and deleting local files or data. The malware includes anti-analysis and environmental-awareness features: it checks for virtual machines and common analysis or monitoring tools including Wireshark, ProcMon/Procmon, Fiddler, and in some reporting Ollydbg, and terminates if it detects a sandbox or researcher environment. MeowMeow’s malicious functionality is also described as parameter-gated in the infection chain, activating only when executed with a specific parameter.

ClearSky reported that both BadPaw and MeowMeow were obfuscated with the .NET Reactor packer/obfuscator to hinder static analysis and reverse engineering, and that the broader campaign used stealth features such as sandbox evasion and staged delivery. The activity was attributed with high confidence to a Russia-linked or Russian state-aligned cyberespionage actor, and with lower or moderate confidence specifically to APT28 (Fancy Bear, Forest Blizzard, Blue Delta), based on Ukrainian targeting, geopolitical lures, Russian-language code artifacts, and tradecraft overlap with prior Russian operations. The reporting did not identify specific victim organizations or confirm attack success.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
APT28

BadPaw then facilitates the subsequent installation of the advanced MeowMeow backdoor, which has file enumeration and data reading, writing, and deletion capabilities.

via scworldscworld.com
MITRE ATT&CK

Techniques & procedures

16 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1566PhishingEvidence1

The attack chain begins with a phishing email carrying a link to a ZIP archive. When opened, an HTA file displays a Ukrainian-language lure about border crossing appeals while secretly launching the infection chain.

T1566.002Spearphishing LinkEvidence6

“The attack chain initiates with a phishing email containing a link to a ZIP archive. Once extracted, an initial HTA file displays a lure document…”

Execution

6 techniques
T1053.005Scheduled TaskEvidence1

“…establishes persistence through a scheduled task.”

T1059.001PowerShellEvidence1

"...MeowMeow is equipped to remotely execute PowerShell commands on the compromised host..."

T1059.005Visual BasicEvidence1

“A VBS script then retrieves hidden payload data embedded within an image using steganography…”

T1059.007JavaScriptEvidence1

“Once extracted, an initial HTA file displays a lure document…”

T1204User ExecutionEvidence1

“Once extracted, an initial HTA file displays a lure document…”

T1204.002Malicious FileEvidence4

"... link redirecting to a ZIP archive containing a Ukrainian border checkpoint permit that triggers the download of the BadPaw loader"

Persistence

1 technique
T1053.005Scheduled TaskEvidence1

“…establishes persistence through a scheduled task.”

Privilege Escalation

1 technique
T1053.005Scheduled TaskEvidence1

“…establishes persistence through a scheduled task.”

Stealth

3 techniques
T1027Obfuscated Files or InformationEvidence2

“both malware strains use the .NET Reactor packer… to hinder static analysis and reverse engineering.”

T1036MasqueradingEvidence1

"...drops a decoy document as a distraction mechanism..."

T1497Virtualization/Sandbox EvasionEvidence4

"...after checking that it's running on an actual endpoint... and no forensic and monitoring tools like Wireshark, Procmon, Ollydbg, and Fiddler are running..."

Discovery

3 techniques
T1012Query RegistryEvidence1

“the HTA file performs an environmental check by inspecting… HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallDate”

T1083File and Directory DiscoveryEvidence3

"... MeowMeow backdoor, which has file enumeration ... capabilities"

T1497Virtualization/Sandbox EvasionEvidence4

"...after checking that it's running on an actual endpoint... and no forensic and monitoring tools like Wireshark, Procmon, Ollydbg, and Fiddler are running..."

Command and Control

2 techniques
T1071Application Layer ProtocolEvidence3

“Upon establishing command-and-control (C2) communication, the loader deploys MeowMeow…”

T1105Ingress Tool TransferEvidence2

“the infection triggers the download of BadPaw… [and] fetch and deploy a sophisticated backdoor called MeowMeow.”

Impact

1 technique
T1565Data ManipulationEvidence1

“…can read, write or delete data on the compromised machine.”

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping16

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.