The new DRILLAPP backdoor has appeared in a cyberattack campaign targeting Ukrainian entities, using innovative techniques via the Microsoft Edge browser for covert espionage. The campaign, detected by S2 Grupo ’s threat intelligence team LAB52 in February 2026 , appears to be linked to Russian hackers and shows overlap with previous activities by the Laundry Bear group (also known as UAC-0190 or Void Blizzard ). This new threat represents a significant escalation in the cyberwarfare being waged against Ukraine, as attackers continue to evolve their tactics to remain undetected.
See also: Microsoft Edge 134: Better speed and performance

The DRILLAPP campaign represents a significant development in cyberattack tactics, as it leverages the Chrome DevTools Protocol (CDP) to bypass browser security restrictions. The attackers are using judicial and charitable themes as bait, primarily targeting Ukrainian defense and government entities. The malware operates as a lightweight JavaScript-based backdoor that runs through the Edge browser in headless mode, giving attackers extensive spying capabilities. This approach is particularly dangerous because it exploits a trusted and widely used browser, making detection extremely difficult for traditional security systems.
The first version of the campaign was detected in early February 2026 and used Windows shortcut (LNK) files to create HTML Application (HTA) in the temporary folder. These files were copied to the Windows Startup to maintain their presence on the system, ensuring that the malware would automatically restart after each system reboot. The attack chain displayed URLs containing baits related to the Starlink or the Ukrainian charity Come Back Alive Foundation. These topics were strategically chosen to exploit the interest of Ukrainian citizens in communication technologies and charitable activities during the war.
Technical details and capabilities of DRILLAPP
The DRILLAPP backdoor runs with specific parameters that grant it extensive access to the system: –no-sandbox, –disable-web-security, –allow-file-access-from-files, –use-fake-ui-for-media-stream, –auto-select-screen-capture-source=true, and –disable-user-media-security. These parameters allow the malware to access the local file system, as well as the camera, microphone, and screenshots without requiring user interaction. Using these parameters is an extremely dangerous tactic, as it bypasses all of the built-in security mechanisms that Microsoft to protect users.
See also: Microsoft Edge: Secure password deployment for businesses

When first executed, the malware creates a device fingerprint using the canvas fingerprinting and uses Pastefy as a dead drop resolver to retrieve a WebSocket URL used for command-and-control (C2). The malware transmits the fingerprint data along with the victim's country, which is determined by the machine's time zone. It specifically checks whether the time zones correspond to the United Kingdom, Russia, Germany, France, China, Japan, United States, Brazil, India, Ukraine, Canada, Australia, Italy, Spain , and Poland. This geographic control suggests that the attackers have specific targets and are trying to avoid attention in certain regions.
The second version of the campaign, detected in late February 2026 , abandoned LNK files in favor of Windows Control Panel modules , while keeping the infection sequence largely intact. Another notable change involved the backdoor itself , which was upgraded to allow recursive file enumeration , batch file uploads , and arbitrary file download . These improvements demonstrate the rapid evolution of the DRILLAPP malware and the dedication of its creators to improving its capabilities. As LAB52 explains , “for security reasons, JavaScript does not allow remote file downloads. This is why attackers use the Chrome DevTools Protocol (CDP) , an internal protocol of Chromium -based browsers that can only be used when the –remote-debugging-port parameter is enabled.”
Protection and threat response strategies
To effectively protect against DRILLAPP and similar threats, organizations should adopt a multi-layered security approach. First, it is critical to disable browser debugging ports via Group Policy or other management tools, thereby preventing malware from using CDP . Second, endpoint detection and response (EDR) systems should be configured to monitor for abnormal browser processes running with debugging parameters. Third, implementing strict email filters for LNK , CPL , HTA , and JavaScript files can prevent initial infection. Finally, regular user education about social engineering techniques used by forensic and charitable organizations is essential to strengthen the human line of defense.
See also: Ukraine: APT28 installs BadPaw Loader and MeowMeow Backdoor

The DRILLAPP backdoor is believed to be still in the early stages of development. An early variant of the malware detected on January 28, 2026 was observed to simply communicate with the “gnome.com” domain instead of downloading the main payload from Pastefy. This suggests that the attackers were conducting tests before fully deploying the campaign, which offers the cybersecurity community a rare opportunity to track the evolution of a threat from its earliest stages.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
