Newly documented BadPaw loader and MeowMeow backdoor mark a refinement, not a pause, in Moscow's cyber campaign against Ukrainian networks.

Intelligence Lead

Israeli cybersecurity firm ClearSky has exposed a targeted Russian cyber campaign against Ukraine built around two previously undocumented malware tools, a loader named BadPaw and a backdoor named MeowMeow. The operation has been attributed with moderate confidence to APT28, the Russian military intelligence-linked threat actor also tracked as Fancy Bear, and it demonstrates that Moscow's cyber directorate continues to invest in new tradecraft even as the ground war grinds on.

Situation Report

According to ClearSky's published research, the campaign begins with a phishing email carrying a link to a ZIP archive. Inside is a malicious document written in Ukrainian, disguised as a permit authorizing passage through a Ukrainian border checkpoint, a lure calibrated to wartime bureaucratic realities and civilian movement anxieties. Opening the archive triggers a loader, BadPaw, which subsequently deploys MeowMeow, a backdoor capable of checking for the presence of specific files and reading, writing, or deleting data on the compromised machine.

Both tools incorporate detection-evasion mechanisms, according to the researchers, and Russian-language strings recovered from the source code reinforce the assessment that the operation originates with a Russian-speaking developer team. The Record, Security Affairs, and The Hacker News have independently reported on the ClearSky findings, with several outlets noting the campaign's overlap with techniques previously observed in APT28 operations.

The attribution to APT28 specifically, rather than to Russia's cyber apparatus broadly, is assessed with moderate rather than high confidence. ClearSky bases the judgment on targeting footprint, the geopolitical calibration of the phishing lure, and technical overlaps with prior Russian state-linked activity, not on a single definitive indicator such as reused infrastructure previously fingerprinted to the group.

Background & Context

APT28 has operated as one of the most persistent Russian state-linked cyber units targeting Ukraine since well before the 2022 invasion, with a track record spanning credential-harvesting operations, wiper malware deployment, and influence operations timed to battlefield and diplomatic developments. Ukrainian and allied cyber defenders have tracked a steady cadence of new malware families from Russian-aligned actors throughout the war, reflecting an arms race in which each disclosed toolset forces adversaries to retool rather than reuse compromised infrastructure.

The border-permit lure is notable in this context. Wartime document-based social engineering, exploiting the genuine bureaucratic friction Ukrainian civilians and officials navigate daily, has become a recurring feature of Russian-aligned phishing campaigns, distinguishing this activity from more generic financially motivated cybercrime.

Analysis & Assessment

The emergence of BadPaw and MeowMeow indicates Russian state-linked cyber units are sustaining a dedicated development pipeline for Ukraine-specific tooling rather than relying on legacy malware families, an investment pattern consistent with a long-duration conflict in which cyber operations run as a persistent, parallel line of effort alongside kinetic operations. The file manipulation capability built into MeowMeow suggests the operators' objectives extend beyond passive intelligence collection toward positioning for potential data destruction or manipulation, a capability profile that historically precedes more disruptive follow-on activity from Russian state-linked actors against Ukrainian infrastructure.

The moderate confidence attribution to APT28 rather than a newly identified actor is itself analytically significant. It suggests Russian military intelligence continues to prioritize deniability and technical novelty over operational efficiency, accepting the cost of building fresh tooling to reduce the risk of detection based on previously catalogued indicators. This pattern is likely to continue as Ukrainian and allied threat intelligence firms improve detection of legacy APT28 infrastructure.