logo

ClearSky report on BadPaw and MeowMeow Russian malware

ID: dca03f33-fe22-4149-a273-6100d3efa28c

STIX ID: report--dca03f33-fe22-4149-a273-6100d3efa28c

Threat Score

85/100

Uploaded: 2026-08-11

Published Date: 2026-03-02

Last Modified Date: 2026-03-02

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ClearSky researchers describe a March 2026 Russian-aligned cyber campaign against Ukrainian targets that uses phishing to deliver a ZIP/HTA infection chain which extracts a .NET loader (BadPaw) via steganography and then retrieves a persistent backdoor (MeowMeow). Both binaries are protected with .NET Reactor and require specific runtime parameters to activate malicious functionality; they include extensive sandbox and tooling checks, C2 callbacks to virtualdailyplanner.pro, and delivered artifacts/hashes and indicators for detection and response.