Threat Intelligence, Malware

Novel DRILLAPP backdoor tapped in Russia-linked attacks against Ukraine

Security Affairs reports that organizations across Ukraine have been targeted with Russia-linked attacks spreading the novel DRILLAPP spyware as part of a cyberespionage campaign that also exploited Microsoft Edge debugging for stealth since February.

Attacks which were attributed with low confidence to Russian advanced persistent threat operation Laundry Bear, also known as Void Blizzard and UAC-0190 involved the use of various lures to distribute the DRILLAPP backdoor, according to a report from S2 Grupo's LAB52 threat intelligence team. While illicit LNK files using Starlink installation images and charity lures have been tapped to execute the initial variant of DRILLAPP and run Microsoft Edge in headless mode to obtain local file access, camera, microphone, and screen capture permissions, threat actors later delivered an updated DRILLAPP variant through Control Panel modules serving as executable DLLs using military lures. Such a DRILLAPP variant was observed to have included batch uploading, recursive file listing, and remote file downloading capabilities.

"The analysis conducted indicates that DRILLAPP is a recent artifact that is still in an early stage of development. One of the most notable aspects is the use of the browser to deploy a backdoor, which suggests that the attackers are exploring new ways to evade detection," said researchers.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds