BADHATCH is a Windows backdoor used by the financially motivated threat group FIN8 and first publicly documented in 2019. It supports post-compromise operations including command execution, reconnaissance, privilege escalation, lateral movement, file transfer, screenshot capture, and data exfiltration. It has been deployed in intrusions affecting insurance, retail, technology, chemical, and financial organizations across multiple countries.
BADHATCH is deployed through downloaded PowerShell scripts and a multistage loading chain involving a .NET loader, architecture-specific shellcode, and an embedded compressed DLL. Its components can execute in memory and inject into legitimate Windows processes using asynchronous procedure calls or remote-thread creation. Persistence mechanisms include WMI event subscriptions and scheduled tasks. Privilege-elevation functionality includes privileged-token impersonation and UAC bypass through the CMSTPLUA COM interface and SilentCleanup scheduled task. Version 2.14 additionally supports operator-supplied NTLM pass-the-hash functionality in 64-bit builds.
The backdoor provides command-shell and PowerShell execution modes, in-memory DLL loading, system and user discovery, domain administrator enumeration, remote WMI queries, connectivity checks, and TCP port discovery. It can upload and download files, capture screenshots, and exfiltrate information over its command-and-control channel. Communications use TLS and support SOCKS4, SOCKS5, HTTP, and reverse proxying. Evasion features include encoded PowerShell commands, encrypted loader components, impersonation of legitimate Microsoft update traffic, and suspension of the Windows Event Log service's main thread. Observed deployment occurs after compromise; the initial access mechanism in investigated FIN8 intrusions was not established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“The FIN8 group uses, among other tools, a fully featured backdoor called BADHATCH, first documented by GIGAMON in 2019.”
35 distinct techniques documented for this family, organized by ATT&CK tactic.
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor associated with FIN8 that researchers said was used in connection with White Rabbit activity.
Contains an embedded second-stage DLL payload within its first stage.
Backdoor that gains persistence using schtasks.exe.
Backdoor capable of executing commands on a compromised host via PowerShell.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.