BadPaw, also known as CINDERBLOT, is a Windows malware loader implemented in .NET Framework 4.6. It establishes command-and-control communications to retrieve and deploy additional malicious components, including the MeowMeow backdoor. BadPaw has been used in Russian state-aligned phishing campaigns targeting Ukrainian organizations, with activity documented in early 2026.
Its delivery chain begins with phishing emails linking to ZIP archives containing disguised HTML Applications and Ukrainian-language border-crossing decoys. The initial scripts display a decoy document, perform environment checks, and establish scheduled-task persistence. A subsequent VBScript extracts the BadPaw executable from an image containing steganographically concealed payload data. BadPaw then contacts attacker infrastructure and reconstructs downloaded components for deployment.
BadPaw masquerades as a functional Windows Forms regular-expression testing utility. Its malicious logic is gated behind a specific launch parameter; execution outside the intended infection chain instead exposes benign-looking GUI behavior. Defensive measures include .NET Reactor obfuscation, anti-debugging and assembly-integrity checks, sandbox detection, timing and uptime checks, and runtime reconstruction of API names. It gathers hardware and operating-system information through WMI to generate a deterministic victim identifier. Its task-based command-and-control design uses HTTPS and cryptographic routines for payload protection and key exchange.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
February – April 2026: BadPaw aka CINDERBLOT (.NET-based loader)
At the time of analysis, the file is recognized as malicious by only nine antivirus engines. We have named this malware “BadPaw”. Its primary objective is to establish communication with a Command and Control (C2) server to download additional malicious components.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
BadPaw builds a comprehensive victim profile through seven WMI queries via the SOS class
To ensure persistence on the infected system, a scheduled task is created to execute the VBS file.
An additional layer of defense employed by BadPaw is the use of .NET Reactor, a commercial protection and obfuscation tool for .NET assemblies.
LibHelperDemo[.]vbs accesses the accompanying image file to extract hidden data, a technique known as steganography.
Layer 5: API String Splitting -- Win32 API names are split across the .NET #US heap ... These are reassembled at runtime via Marshal.GetDelegateForFunctionPointer. Static string scanners see nothing.
The retrieved ZIP archive contains a file with an .html extension; however, this is a masquerade. Technical analysis reveals the file is actually an HTA (HTML Application).
Process Injection Chain ... OpenProcess obtains a handle to the target, VirtualAlloc reserves memory, WriteProcessMemory writes the payload, and VirtualProtect flips the page to executable.
The PE compilation timestamp is falsified to 2039, an anti-forensics measure.
Technical analysis reveals the file is actually an HTA (HTML Application). Upon execution, the HTA file drops and opens a decoy document...
Layer 4: Sandbox Detection -- The Sand class implements IsSandBox() for environment fingerprinting, CheckSleep() for timing-based detection ... and a Windows EventLog reader that checks for sandbox-indicator events. System uptime analysis rounds it out -- fresh VMs have short uptimes.
By querying this value, the malware calculates the "age" of the operating system. If the system was installed less than ten days prior to execution, the malware terminates.
Defender Reconnaissance Before any malicious activity, BadPaw queries the registry for the state of Windows Defender: HKLM\SOFTWARE\Microsoft\AMSI ... HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\PassiveMode ...
Before phoning home, BadPaw builds a comprehensive victim profile through seven WMI queries ... MAC address, Disk serial number, Motherboard serial, BIOS information, Computer system details, OS identity string, Process ID.
Layer 4: Sandbox Detection -- The Sand class implements IsSandBox() for environment fingerprinting, CheckSleep() for timing-based detection ... and a Windows EventLog reader that checks for sandbox-indicator events. System uptime analysis rounds it out -- fresh VMs have short uptimes.
By querying this value, the malware calculates the "age" of the operating system. If the system was installed less than ten days prior to execution, the malware terminates.
“Upon establishing command-and-control (C2) communication, the loader deploys MeowMeow…”
The Task-Based C2 ... GetTaskRequest() -- poll the C2 for pending commands ... Transport is HTTPS with custom User-Agent headers
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
.NET loader listed among UAC-0099's tools used during February–April 2026.
One of a newly exposed malware duo used in a Russian campaign targeting Ukraine.
A .NET Framework 4.6 trojan downloader that masquerades as a legitimate regex testing utility while using layered anti-analysis protections including obfuscation, anti-debugging, anti-tamper checks, sandbox detection, API string splitting, WMI-based host fingerprinting, Defender reconnaissance, structured HTTPS C2 communications, and a process injection chain to deploy an embedded payload.
A newly reported malware family used in a phishing campaign targeting Ukrainian organizations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.