BadRabbit is a Windows ransomware family first observed in October 2017 during a disruptive outbreak affecting organizations in Eastern Europe and Russia, including transportation and media entities. It is widely assessed as closely related to the Petya/NotPetya lineage at the codebase level, with notable similarities in build tooling and propagation tradecraft, though common authorship has been treated with lower confidence than the technical overlap itself.
Initial infection was commonly achieved through compromised websites presenting a fake Adobe Flash Player update, requiring user execution rather than a zero-click exploit for first-stage compromise. After execution, BadRabbit deployed additional components including credential-harvesting tooling and legitimate DiskCryptor components, then established mechanisms to continue execution and trigger a reboot.
Within victim networks, BadRabbit spread laterally over SMB using a combination of stolen or guessed credentials, mimikatz-like credential theft, brute-force attempts, WMI, and service-control mechanisms. Reporting also identified use of the EternalRomance exploit associated with MS17-010 during propagation, while finding no evidence of EternalBlue use in the campaign. The malware used named-pipe-based inter-process communication between components and relied heavily on legitimate Windows administration features to move across hosts.
For impact, BadRabbit modified the master boot record, rebooted infected systems into attacker-controlled code, and performed disk and file encryption, rendering systems inoperable until recovery or decryption. It created ransom-note artifacts and scheduled tasks to support execution flow and reboot timing. Although presented as ransomware and technically enabling recovery in principle, it caused major operational disruption and has also been discussed in some analyses as part of the broader trend of pseudo-ransomware or destructive campaigns associated with Russian GRU-linked activity, particularly Sandworm/TeleBots, though attribution should be distinguished from purely technical characterization.
BadRabbit primarily targeted Windows enterprise environments and is notable for combining social engineering, credential theft, worm-like lateral movement, and destructive-enough ransomware effects to rapidly saturate internal networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Cisco Talos was alerted to a widescale ransomware campaign affecting organizations across eastern Europe and Russia... the dropper contains the BadRabbit ransomware. Once installed there is an SMB component used for lateral movement and further infection.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
They used “social engineering by sending a malicious executable application, from the ‘Locky’ or ‘BadRabbit’ (computer virus) families, hidden in an e-mail...”
The attack using the BadRabbit family in October 2017.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Talos assesses with high confidence that a fake Flash Player update is being delivered via a drive-by-download and compromising systems.
They used “social engineering by sending a malicious executable application, from the ‘Locky’ or ‘BadRabbit’ (computer virus) families, hidden in an e-mail and in the form of a file that apparently would come from other government institutions, regarding the threat of COVID-19.”
They used “social engineering by sending a malicious executable application, from the ‘Locky’ or ‘BadRabbit’ (computer virus) families, hidden in an e-mail and in the form of a file that apparently would come from other government institutions, regarding the threat of COVID-19.”
It is performed by Microsoft Windows legitimate features, via: ... WMI
The malware then creates a scheduled task with the parameters shown in the screenshot below... the malware creates a second scheduled task that is responsible for rebooting the system.
The dropper ... requires a user to facilitate the infection and does not use any exploit to compromise the system directly.
That subtly powerful hacking tool was designed to siphon a Windows user's password out of the ephemeral murk of a computer's memory, so that it could be used to gain repeated access to that computer, or to any others that victim's account could access on the same network.
It is performed by Microsoft Windows legitimate features, via: SVCCTL: the remote service management
a new variant of that code locks up hundreds of machines and handicaps infrastructure
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a targeted ransomware family with technique similarities to OlympicDestroyer.
Ransomware family referenced as one of the malicious payloads used in phishing-style delivery disguised as government COVID-19 communications.
Wiper malware with ransomware-like features, used to disrupt organizations, particularly in industrial and critical infrastructure sectors.
Ransomware that encrypts hard drives and renders systems inoperable, causing operational disruption across transportation, finance, and media entities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.