MeowMeow is a Windows backdoor used in a targeted cyber-espionage campaign against Ukrainian organizations. It has been observed as the final payload in a multi-stage intrusion chain in which a phishing email leads victims to a ZIP archive containing a disguised HTA-based loader and subsequent components. In that chain, a .NET loader known as BadPaw retrieves and deploys MeowMeow after establishing command-and-control communications.
MeowMeow is designed for persistent remote access and post-compromise host manipulation. Reported capabilities include remote PowerShell execution and file-system operations such as checking for file existence and reading, writing, and deleting local data. The malware uses execution gating, activating its malicious logic only when launched with a specific parameter supplied by the infection chain, while presenting benign decoy behavior when run outside its intended context.
The malware incorporates multiple anti-analysis and defense-evasion features. It is obfuscated with .NET Reactor, checks for virtualized or sandboxed environments, and looks for common analysis and monitoring tools including Wireshark, ProcMon, OllyDbg, and Fiddler. If it detects signs of a researcher or sandbox environment, it terminates execution. The broader campaign also used decoy user-interface elements and staged delivery to frustrate reverse engineering and conceal malicious activity.
The activity associated with MeowMeow has been assessed with high confidence as Russian state-aligned and with lower confidence as potentially linked to APT28, also known as Fancy Bear or Forest Blizzard. The campaign’s victimology, Ukrainian-themed lures, Russian-language code artifacts, and tradecraft overlap with prior Russian espionage operations support that assessment. MeowMeow appears intended for covert access and data handling on compromised Ukrainian systems rather than disruptive or destructive effects.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The final component is an additional executable, dropped after the ASCII data is converted back into a standard string. This file, named MeowMeowProgram[.]exe, serves as a persistent backdoor.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
An additional layer of defense employed by BadPaw is the use of .NET Reactor, a commercial protection and obfuscation tool for .NET assemblies.
The retrieved ZIP archive contains a file with an .html extension; however, this is a masquerade. Technical analysis reveals the file is actually an HTA (HTML Application).
These capabilities include verifying the existence of specific files, as well as the ability to delete, write, and read data from the local storage.
It actively scans for virtual machines and common analysis tools such as Wireshark, ProcMon, and Fiddler, immediately terminating its execution if a sandbox or researcher environment is detected.
“the HTA file performs an environmental check by inspecting… HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallDate”
Additionally, the backdoor supports a variety of file system operations. These capabilities include verifying the existence of specific files...
It actively scans for virtual machines and common analysis tools such as Wireshark, ProcMon, and Fiddler, immediately terminating its execution if a sandbox or researcher environment is detected.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Companion malware in a newly exposed duo used in a Russian campaign targeting Ukraine.
A newly reported malware family used in a phishing campaign targeting Ukrainian organizations.
One of a newly reported malware pair used in a Russian campaign targeting Ukraine.
Russian APT targets Ukraine with BadPaw and MeowMeow malware
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.