A Russia-linked cyber-espionage campaign targeted Ukrainian entities with a JavaScript-based backdoor called DRILLAPP, using lures themed around Starlink terminal verification and the Come Back Alive Foundation charity. Researchers linked the activity to Laundry Bear—also tracked as Void Blizzard and UAC-0190—and said the operation shared tradecraft with earlier campaigns against Ukrainian defense-related targets. The malware was observed in February 2026 and was designed for surveillance and remote access, including file upload and download, microphone recording, and webcam image capture.
The intrusion chain used malicious LNK files to create an HTA file in a temporary directory, fetch obfuscated scripts from Pastefy, and establish persistence by copying shortcuts into the Windows Startup folder. The payload then executed through Microsoft Edge in headless mode with permissive flags such as --no-sandbox, --disable-web-security, --allow-file-access-from-files, --use-fake-ui-for-media-stream, and --disable-user-media-security, enabling access to the local file system, camera, microphone, and potentially screen capture without normal user prompts. Researchers said the browser-based approach likely helps the attackers blend malicious activity with legitimate browser access to sensitive device features.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
On March 16, 2026, LAB52 publicly reported the February campaign, describing DRILLAPP as a JavaScript backdoor that abuses Microsoft Edge headless mode, browser debugging, and media-access features to capture files, audio, webcam images, and screen content.
A later February 2026 DRILLAPP variant changed delivery to Windows Control Panel module files while retaining the Edge-based execution chain. It also added recursive file enumeration, batch uploads, arbitrary downloads, and broader file-management functions.
The first observed campaign variant used LNK files to drop HTML or HTA content and retrieve obfuscated remote scripts hosted on Pastefy, establishing the browser-based backdoor on victim systems.
In February 2026, a cyber-espionage campaign targeted Ukrainian organizations using judicial, charity, and Starlink-themed lures to deliver the DRILLAPP backdoor. Researchers linked the activity with low confidence to the Russian-aligned Laundry Bear group based on overlaps with prior tradecraft used against Ukraine.
Researchers identified an earlier DRILLAPP sample dated January 28, 2026 that only communicated with gnome[.]com, indicating the malware was still in an early development stage before the broader campaign.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcethehackernews.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.