Russian State-Linked Hackers Deploy Backdoors Against Ukraine

Suspected Russian state‑aligned actors used phishing emails from ukr[.]net to deliver a BadPaw loader and the MeowMeow backdoor to Ukrainian targets. MeowMeow can read, write and delete local files and includes sandbox and VM checks to evade detection. ClearSky links the campaign to Russian state‑aligned operators, with low confidence attribution to APT28.

Part of the PlainSec briefing for 2026-03-05

Sources