BadRabbit is Windows ransomware with worm-like propagation capabilities that caused a major outbreak in October 2017, primarily affecting Russia, Ukraine, and other parts of Eastern Europe. It disrupted transportation infrastructure, media organizations, and financial institutions, including the Kyiv metro and Odessa airport. The October 2017 operation has been publicly attributed to Russia’s GRU unit associated with Sandworm and TeleBots.
Its principal initial infection vector was compromised websites distributing a fake Adobe Flash Player update. Installation required user interaction rather than exploitation of the browser or operating system. Subsequent distribution has also included phishing emails carrying malicious executables disguised as government communications. Once installed, BadRabbit spreads through enterprise networks using SMB, WMI, stolen credentials, weak-password brute forcing, and the EternalRomance exploit against vulnerabilities covered by MS17-010. It includes Mimikatz-like credential-dumping components for both 32-bit and 64-bit Windows systems. EternalBlue was not identified in the October 2017 campaign.
BadRabbit encrypts individual files and performs full-disk encryption using legitimate DiskCryptor components. It modifies the Master Boot Record to display an attacker-controlled ransom screen and creates scheduled tasks, including a task that reboots the infected system. Its components communicate through named pipes. BadRabbit shares a core codebase and similar build tooling with NotPetya, also known as Nyetya, but differs by technically supporting data recovery through decryption rather than functioning solely as an irreversible wiper.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The MS17-010 vulnerabilities persist within enterprise networks and continue to be used by multiple families of ransomware today including Ryuk, SamSam, Satan, BadRabbit, and Katyusha.
The MS17-010 vulnerabilities persist within enterprise networks and continue to be used by multiple families of ransomware today including Ryuk, SamSam, Satan, BadRabbit, and Katyusha.
The MS17-010 vulnerabilities persist within enterprise networks and continue to be used by multiple families of ransomware today including Ryuk, SamSam, Satan, BadRabbit, and Katyusha.
The MS17-010 vulnerabilities persist within enterprise networks and continue to be used by multiple families of ransomware today including Ryuk, SamSam, Satan, BadRabbit, and Katyusha.
Cisco Talos was alerted to a widescale ransomware campaign affecting organizations across eastern Europe and Russia... the dropper contains the BadRabbit ransomware. Once installed there is an SMB component used for lateral movement and further infection.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
They used “social engineering by sending a malicious executable application, from the ‘Locky’ or ‘BadRabbit’ (computer virus) families, hidden in an e-mail...”
The attack using the BadRabbit family in October 2017.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Talos assesses with high confidence that a fake Flash Player update is being delivered via a drive-by-download and compromising systems.
They used “social engineering by sending a malicious executable application, from the ‘Locky’ or ‘BadRabbit’ (computer virus) families, hidden in an e-mail and in the form of a file that apparently would come from other government institutions, regarding the threat of COVID-19.”
They used “social engineering by sending a malicious executable application, from the ‘Locky’ or ‘BadRabbit’ (computer virus) families, hidden in an e-mail and in the form of a file that apparently would come from other government institutions, regarding the threat of COVID-19.”
It is performed by Microsoft Windows legitimate features, via: ... WMI
The malware then creates a scheduled task with the parameters shown in the screenshot below... the malware creates a second scheduled task that is responsible for rebooting the system.
The dropper ... requires a user to facilitate the infection and does not use any exploit to compromise the system directly.
That subtly powerful hacking tool was designed to siphon a Windows user's password out of the ephemeral murk of a computer's memory, so that it could be used to gain repeated access to that computer, or to any others that victim's account could access on the same network.
It is performed by Microsoft Windows legitimate features, via: SVCCTL: the remote service management
a new variant of that code locks up hundreds of machines and handicaps infrastructure
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an example of a black-swan ransomware event.
Referenced as a targeted ransomware family with technique similarities to OlympicDestroyer.
Ransomware family referenced as one of the malicious payloads used in phishing-style delivery disguised as government COVID-19 communications.
Wiper malware with ransomware-like features, used to disrupt organizations, particularly in industrial and critical infrastructure sectors.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.