BADHATCH

S1081

Malware.View on attack.mitre.org

About this malware

BADHATCH is a backdoor that has been utilized by FIN8 since at least 2019. BADHATCH has been used to target the insurance, retail, technology, and chemical industries in the United States, Canada, South Africa, Panama, and Italy.

Techniques used35

Procedure examples35

TechniqueProcedure example
T1018
Remote System Discovery

BADHATCH can use a PowerShell object such as, `System.Net.NetworkInformation.Ping` to ping a computer.

T1027.009
Embedded Payloads

BADHATCH has an embedded second stage DLL payload within the first stage of the malware.

T1027.010
Command Obfuscation

BADHATCH malicious PowerShell commands can be encoded with base64.

T1027.015
Compression

BADHATCH can be compressed with the ApLib algorithm.

T1033
System Owner/User Discovery

BADHATCH can obtain logged user information from a compromised machine and can execute the command `whoami.exe`.

T1041
Exfiltration Over C2 Channel

BADHATCH can exfiltrate data over the C2 channel.

T1046
Network Service Discovery

BADHATCH can check for open ports on a computer by establishing a TCP connection.

T1047
Windows Management Instrumentation

BADHATCH can utilize WMI to collect system information, create new processes, and run malicious PowerShell scripts on a compromised machine.

T1049
System Network Connections Discovery

BADHATCH can execute `netstat.exe -f` on a compromised machine.

T1053.005
Scheduled Task

BADHATCH can use `schtasks.exe` to gain persistence.

T1055
Process Injection

BADHATCH can inject itself into an existing explorer.exe process by using `RtlCreateUserThread`.

T1055.001
Dynamic-link Library Injection

BADHATCH has the ability to execute a malicious DLL by injecting into `explorer.exe` on a compromised machine.

T1055.004
Asynchronous Procedure Call

BADHATCH can inject itself into a new `svchost.exe -k netsvcs` process using the asynchronous procedure call (APC) queue.

T1057
Process Discovery

BADHATCH can retrieve a list of running processes from a compromised machine.

T1059.001
PowerShell

BADHATCH can utilize `powershell.exe` to execute commands on a compromised host.

View all 35 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. BitDefender BADHATCH Mar 2021 Open source
    Vrabie, V., et al. (2021, March 10). FIN8 Returns with Improved BADHATCH Toolkit. Retrieved September 8, 2021.
  2. Gigamon BADHATCH Jul 2019 Open source
    Savelesky, K., et al. (2019, July 23). ABADBABE 8BADFOOD: Discovering BADHATCH and a Detailed Look at FIN8's Tooling. Retrieved September 8, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.