Piece of news of the day
ADVANCED SECURITY EUROPA
EOODDRILLAPP Backdoor Targets Ukraine, Abuses Microsoft Edge Debugging for Stealth Espionage
Mar 16, 2026A new cyber campaign targeting Ukrainian entities has been identified, believed to be linked to Russian threat actors.
The campaign uses a malware known as PLUGGYAPE to deploy a JavaScript-based backdoor called DRILLAPP through the Edge browser, allowing for file uploads and downloads, microphone and webcam access.
Two versions of the campaign have been detected, with the second version incorporating upgrades for additional functionalities.
The attackers utilize the Chrome DevTools Protocol to download files remotely.
The use of the browser to deploy the backdoor enables evasion of detection and grants access to sensitive resources like the microphone and camera.

