ClearSky report on BadPaw and MeowMeow Russian malware
ID: dca03f33-fe22-4149-a273-6100d3efa28c
STIX ID: report--dca03f33-fe22-4149-a273-6100d3efa28c
Threat Score
85/100
Uploaded: 2026-08-11
Published Date: 2026-03-02
Last Modified Date: 2026-03-02
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ClearSky researchers describe a March 2026 Russian-aligned cyber campaign against Ukrainian targets that uses phishing to deliver a ZIP/HTA infection chain which extracts a .NET loader (BadPaw) via steganography and then retrieves a persistent backdoor (MeowMeow). Both binaries are protected with .NET Reactor and require specific runtime parameters to activate malicious functionality; they include extensive sandbox and tooling checks, C2 callbacks to virtualdailyplanner.pro, and delivered artifacts/hashes and indicators for detection and response.
