lab52 · Crawled Jul 31, 2026

DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear

31 IoCs 1 Actors
Read original article ↗

AI Summary

LAB52 identified a new cyber espionage campaign targeting Ukrainian entities using a JavaScript-based backdoor named DRILLAPP, delivered via malicious LNK and CPL files. The malware leverages Microsoft Edge in headless mode with permissive command-line flags to enable remote surveillance capabilities including microphone, webcam, and screen capture. The campaign uses lures themed around judicial and charity topics, with infrastructure hosted on public text-sharing services like pastefy.app. Activity shows possible links to the Russian-aligned threat actor Laundry Bear, based on overlapping tactics such as lure themes and hosting patterns.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 31 extracted

Type Value Detail
SHA-256 5b978cdc46afa28d83e532cd19622d9097bebedf87efc4c87bd35d8ffad9e672 Details →
SHA-256 6178b1af51057c0bac75a842afff500a8fa3ed957d79a712a6ef089bec7e7a8b Details →
SHA-256 ac60eefc2607216f8126c0b22b6243f3862ef2bb265c585deee0d00a20a436b3 Details →
SHA-256 e20831cecd763d0dc91fb39f3bd61d17002608c5a40a6cf0bd16111f4e50d341 Details →
SHA-256 ee90b01b16099e0bb23d4653607a3a559590fc8d0c43120b8456fb1860d2e630 Details →
SHA-256 32973ef02e10a585a4a0196b013265e29fc57d8e1c50752f7b39e43b9f388715 Details →
SHA-256 107b2badfc93fcdd3ffda7d3999477ced3f39f43f458dd0f6a424c9ab52681c3 Details →
SHA-256 a545908c931ec47884b5ccfb1f112435f5d0cdac140e664673672c9df9016672 Details →
SHA-256 352f34ea5cc40e2b3ec056ae60fa19a368dbd42503ef225cb1ca57956eb05e81 Details →
SHA-256 c6905bae088982a2b234451b45db742098f2e2ab4fd6ca62c8f4e801160552aa Details →
SHA-256 993d55f60414bf2092f421c3d0ac6af1897a21cc4ea260ae8e610a402bf4c81c Details →
SHA-256 ccb7d999ee4d979e175b8c87e09ccda0cbc93b6140471283e3a1f1f9da33759d Details →
SHA-256 51e86408904c0ca3778361cde746783a0f2b9fd2a6782aa7e062aa597151876e Details →
SHA-256 fb16933b09a4fcca5beff93da05566e924017fb534a2f45caf57b57a633f43a6 Details →
SHA-256 2b5d8f8db5fd38ae1c34807dcba35b057cffa61eb14ba3b558f82eb630480c3f Details →
SHA-256 eb9c1649e01db6a9a94d5d50373e54865d672b14ad6f221c98047c562d3cc0f3 Details →
SHA-256 8c6ea44ce7f4ed4e4e7e19e11b3b345d58785c93b33aa795ddd1b0d753236b05 Details →
SHA-256 66a7828bc8c6c783b2ffa3c906d53f6dae1bbddc019283cc369d7d73247c5181 Details →
SHA-256 886df55794cbca146de96dcc626471b3c097a5c20ba488033b24f4347aa20a14 Details →
SHA-256 9367f4b4d2775ff47279d143dd9a0ef544ddff81946aab33da9350a49f14e1e1 Details →
SHA-256 b891fa118db5190f07b18be46eb9bc10677f9afab1406a7d52ce587522ab3d28 Details →
SHA-256 bad7c6f6ca25363a02eaceb3ed1e378218dc4a246a63d723cfcc5feee3af5056 Details →
SHA-256 21fefc3913d3d2dfde7f0dff54800ca7512eb5df9513b1a457a2af25fdd51b26 Details →
SHA-256 801c47550799831bfb1ac6c5c3fd698be95da19fc85bd65f5d8639f26244d2a9 Details →
SHA-256 6fea579685d2433cedb1c32ef704575dcbc1d0a623769e824023ffccd0dedaae Details →
SHA-256 76eb713e38f145ee68b89f2febd8f9a28bbb2b464da61cb029d84433a0b2c746 Details →
IP 80[.]89[.]224[.]13 Details →
IP 188[.]137[.]228[.]162 Details →
Domain pastefy[.]app Details →
Domain short-link[.]net Details →
Domain iili[.]io Details →

MITRE ATT&CK TTPs 39 techniques

T1003 OS Credential Dumping · Credential Access T1003.001 LSASS Memory · Credential Access T1021.003 Distributed Component Object Model · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1055 Process Injection · Defense Evasion T1056.001 Keylogging · Collection T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1059.007 JavaScript · Execution T1070.004 File Deletion · Defense Evasion T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1071.004 DNS · Command And Control T1074.001 Local Data Staging · Collection T1080 Taint Shared Content · Lateral Movement T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1090 Proxy · Command And Control T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1114 Email Collection · Collection T1132.002 Non-Standard Encoding · Command And Control T1190 Exploit Public-Facing Application · Initial Access T1203 Exploitation for Client Execution · Execution T1204.002 Malicious File · Execution T1485 Data Destruction · Impact T1496 Resource Hijacking · Impact T1530 Data from Cloud Storage · Collection T1539 Steal Web Session Cookie · Credential Access T1552 Unsecured Credentials · Credential Access T1555 Credentials from Password Stores · Credential Access T1557 Adversary-in-the-Middle · Credential Access T1558.003 Kerberoasting · Credential Access T1566 Phishing · Initial Access T1568 Dynamic Resolution · Command And Control T1570 Lateral Tool Transfer · Lateral Movement T1588 Obtain Capabilities · Resource Development