Russia-Linked APT Uses DRILLAPP to Spy on Ukraine
Russia-linked APT groups have intensified efforts against Ukrainian targets by deploying the DRILLAPP backdoor, leveraging Microsoft Edge debugging for discreet espionage. Uncovered in February 2026, the new campaign by Laundry Bear, also known as UAC-0190 or Void Blizzard, mirrors previous Russian-aligned cyber-operations. DRILLAPP employs LNK files to create HTML files that execute obfuscated scripts, exploiting Microsoft Edge’s headless mode to grant unauthorized access to files and media devices. Researchers noted an evolution to CPL files later in February, maintaining similar tactics. These tactics enable remote control and data exfiltration through a browser, providing an avenue for ongoing surveillance while avoiding detection. According to experts, the development of DRILLAPP signifies an exploration of novel methods by Russian-aligned actors to deploy backdoors using common, trusted processes. For further details on how this Russia-linked APT uses DRILLAPP and to stay informed on these cybersecurity threats, read the full article at the link below.
Russia-linked APT uses DRILLAPP backdoor to spy on Ukrainian targets
