MeowMeow is a persistent Windows backdoor deployed by the BadPaw .NET loader in Russian state-aligned cyberespionage campaigns targeting Ukrainian organizations. Identified in March 2026, it enables remote PowerShell command execution and local file operations, including enumeration, existence checks, reading, writing, and deletion.
Delivery uses phishing emails linking to ZIP archives containing a disguised HTML Application and Ukrainian-language border-crossing decoys. The multistage infection chain uses VBScript to extract BadPaw from an image through steganography, establishes persistence through a scheduled task, and ultimately installs MeowMeow.
MeowMeow uses .NET Reactor obfuscation and parameter-gated execution to hinder analysis. When launched outside the intended infection chain, it presents a cat-themed decoy interface rather than activating its malicious functionality. It checks for virtualized environments and analysis tools, including Wireshark, Process Monitor, OllyDbg, and Fiddler, and terminates execution when it detects a sandbox or research environment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
February – April 2026: BadPaw aka CINDERBLOT (.NET-based loader) and MeowMeow (backdoor)
The final component is an additional executable, dropped after the ASCII data is converted back into a standard string. This file, named MeowMeowProgram[.]exe, serves as a persistent backdoor.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
An additional layer of defense employed by BadPaw is the use of .NET Reactor, a commercial protection and obfuscation tool for .NET assemblies.
The retrieved ZIP archive contains a file with an .html extension; however, this is a masquerade. Technical analysis reveals the file is actually an HTA (HTML Application).
These capabilities include verifying the existence of specific files, as well as the ability to delete, write, and read data from the local storage.
It actively scans for virtual machines and common analysis tools such as Wireshark, ProcMon, and Fiddler, immediately terminating its execution if a sandbox or researcher environment is detected.
“the HTA file performs an environmental check by inspecting… HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallDate”
Additionally, the backdoor supports a variety of file system operations. These capabilities include verifying the existence of specific files...
It actively scans for virtual machines and common analysis tools such as Wireshark, ProcMon, and Fiddler, immediately terminating its execution if a sandbox or researcher environment is detected.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor listed among UAC-0099's tools used during February–April 2026.
Companion malware in a newly exposed duo used in a Russian campaign targeting Ukraine.
A newly reported malware family used in a phishing campaign targeting Ukrainian organizations.
One of a newly reported malware pair used in a Russian campaign targeting Ukraine.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.