lab52 · Crawled Jul 31, 2026
DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear
31 IoCs 1 Actors
Read original article ↗
AI Summary
LAB52 identified a new cyber espionage campaign targeting Ukrainian entities using a JavaScript-based backdoor named DRILLAPP, delivered via malicious LNK and CPL files. The malware leverages Microsoft Edge in headless mode with permissive command-line flags to enable remote surveillance capabilities including microphone, webcam, and screen capture. The campaign uses lures themed around judicial and charity topics, with infrastructure hosted on public text-sharing services like pastefy.app. Activity shows possible links to the Russian-aligned threat actor Laundry Bear, based on overlapping tactics such as lure themes and hosting patterns.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 31 extracted
| Type | Value | Detail |
|---|---|---|
| SHA-256 | 5b978cdc46afa28d83e532cd19622d9097bebedf87efc4c87bd35d8ffad9e672 | Details → |
| SHA-256 | 6178b1af51057c0bac75a842afff500a8fa3ed957d79a712a6ef089bec7e7a8b | Details → |
| SHA-256 | ac60eefc2607216f8126c0b22b6243f3862ef2bb265c585deee0d00a20a436b3 | Details → |
| SHA-256 | e20831cecd763d0dc91fb39f3bd61d17002608c5a40a6cf0bd16111f4e50d341 | Details → |
| SHA-256 | ee90b01b16099e0bb23d4653607a3a559590fc8d0c43120b8456fb1860d2e630 | Details → |
| SHA-256 | 32973ef02e10a585a4a0196b013265e29fc57d8e1c50752f7b39e43b9f388715 | Details → |
| SHA-256 | 107b2badfc93fcdd3ffda7d3999477ced3f39f43f458dd0f6a424c9ab52681c3 | Details → |
| SHA-256 | a545908c931ec47884b5ccfb1f112435f5d0cdac140e664673672c9df9016672 | Details → |
| SHA-256 | 352f34ea5cc40e2b3ec056ae60fa19a368dbd42503ef225cb1ca57956eb05e81 | Details → |
| SHA-256 | c6905bae088982a2b234451b45db742098f2e2ab4fd6ca62c8f4e801160552aa | Details → |
| SHA-256 | 993d55f60414bf2092f421c3d0ac6af1897a21cc4ea260ae8e610a402bf4c81c | Details → |
| SHA-256 | ccb7d999ee4d979e175b8c87e09ccda0cbc93b6140471283e3a1f1f9da33759d | Details → |
| SHA-256 | 51e86408904c0ca3778361cde746783a0f2b9fd2a6782aa7e062aa597151876e | Details → |
| SHA-256 | fb16933b09a4fcca5beff93da05566e924017fb534a2f45caf57b57a633f43a6 | Details → |
| SHA-256 | 2b5d8f8db5fd38ae1c34807dcba35b057cffa61eb14ba3b558f82eb630480c3f | Details → |
| SHA-256 | eb9c1649e01db6a9a94d5d50373e54865d672b14ad6f221c98047c562d3cc0f3 | Details → |
| SHA-256 | 8c6ea44ce7f4ed4e4e7e19e11b3b345d58785c93b33aa795ddd1b0d753236b05 | Details → |
| SHA-256 | 66a7828bc8c6c783b2ffa3c906d53f6dae1bbddc019283cc369d7d73247c5181 | Details → |
| SHA-256 | 886df55794cbca146de96dcc626471b3c097a5c20ba488033b24f4347aa20a14 | Details → |
| SHA-256 | 9367f4b4d2775ff47279d143dd9a0ef544ddff81946aab33da9350a49f14e1e1 | Details → |
| SHA-256 | b891fa118db5190f07b18be46eb9bc10677f9afab1406a7d52ce587522ab3d28 | Details → |
| SHA-256 | bad7c6f6ca25363a02eaceb3ed1e378218dc4a246a63d723cfcc5feee3af5056 | Details → |
| SHA-256 | 21fefc3913d3d2dfde7f0dff54800ca7512eb5df9513b1a457a2af25fdd51b26 | Details → |
| SHA-256 | 801c47550799831bfb1ac6c5c3fd698be95da19fc85bd65f5d8639f26244d2a9 | Details → |
| SHA-256 | 6fea579685d2433cedb1c32ef704575dcbc1d0a623769e824023ffccd0dedaae | Details → |
| SHA-256 | 76eb713e38f145ee68b89f2febd8f9a28bbb2b464da61cb029d84433a0b2c746 | Details → |
| IP | 80[.]89[.]224[.]13 | Details → |
| IP | 188[.]137[.]228[.]162 | Details → |
| Domain | pastefy[.]app | Details → |
| Domain | short-link[.]net | Details → |
| Domain | iili[.]io | Details → |
MITRE ATT&CK TTPs 39 techniques
T1003 OS Credential Dumping · Credential Access T1003.001 LSASS Memory · Credential Access T1021.003 Distributed Component Object Model · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1055 Process Injection · Defense Evasion T1056.001 Keylogging · Collection T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1059.007 JavaScript · Execution T1070.004 File Deletion · Defense Evasion T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1071.004 DNS · Command And Control T1074.001 Local Data Staging · Collection T1080 Taint Shared Content · Lateral Movement T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1090 Proxy · Command And Control T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1114 Email Collection · Collection T1132.002 Non-Standard Encoding · Command And Control T1190 Exploit Public-Facing Application · Initial Access T1203 Exploitation for Client Execution · Execution T1204.002 Malicious File · Execution T1485 Data Destruction · Impact T1496 Resource Hijacking · Impact T1530 Data from Cloud Storage · Collection T1539 Steal Web Session Cookie · Credential Access T1552 Unsecured Credentials · Credential Access T1555 Credentials from Password Stores · Credential Access T1557 Adversary-in-the-Middle · Credential Access T1558.003 Kerberoasting · Credential Access T1566 Phishing · Initial Access T1568 Dynamic Resolution · Command And Control T1570 Lateral Tool Transfer · Lateral Movement T1588 Obtain Capabilities · Resource Development