Executive Summary
In May 2026, a new campaign attributed to a Russian-speaking operator was identified deploying an upgraded variant of the 'Meow' malware. Unlike previous versions, this variant functions as a persistent Remote Access Trojan (RAT) that uses fileless execution to evade detection. The campaign targets users in Asia, North America, and Oceania, specifically within the technology, media, and business services sectors.
The attack utilizes the 'ClickFix' technique, where victims are socially engineered into executing a curl command from their terminal. The malware performs CIS-geofencing to avoid Russian targets, harvests browser and system credentials via fake dialogs, and employs a sophisticated routine to overwrite legitimate cryptocurrency wallet applications with trojanized versions. The inclusion of a persistent C2 beaconing loop allows the operator to maintain long-term access and execute arbitrary code on infected hosts.
