BADNEWS is a Windows backdoor used for cyberespionage, associated with Patchwork, also known as Dropping Elephant or APT-C-09, and deployed in the MONSOON APT campaign. It has been distributed through malicious Microsoft Office documents, including RTF documents exploiting CVE-2015-1641. Spearphishing activity deploying closely matching BADNEWS code has also used CVE-2017-0261. Lures have included Pakistani government material, India–Pakistan tensions, Kashmir-related news, and employment themes.
The malware provides remote command execution through the Windows command shell, downloads and executes additional payloads, and supports process hollowing. Its surveillance capabilities include keylogging and operator-requested screenshots that are transmitted to command-and-control infrastructure. BADNEWS automatically harvests selected documents from local and mapped drives, monitors newly connected USB storage, and stages collected files locally for exfiltration. Observed variants support file upload and download, keylog retrieval, and exfiltration of documents stolen from removable media; USB access is a collection mechanism rather than an established propagation vector.
BADNEWS communicates over HTTP and can retrieve command-and-control configuration through dead drop resolvers hosted on legitimate services, including GitHub, blogs, forums, and RSS feeds. Communications use custom rotation and XOR transformations, hexadecimal conversion, and Base64 encoding. Persistence mechanisms include registry-based autostart and recurring scheduled tasks. Execution commonly relies on DLL side-loading through legitimate signed Java or VMware executables. Additional evasion behaviors include masquerading under legitimate-looking names, string obfuscation, delayed execution, and dynamic API resolution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The document contains a file called image1.eps that the report says exploits “CVE-2017-0261”. The exploit executes shellcode that drops three executable files and launches VMWareCplLauncher.exe. | Both its capabilities and its code are practically the same as those described by Unit42 in reference to the BadNews threat.
This malicious RTF file takes advantage of the vulnerability CVE-2015-1641. Upon successful exploitation, it drops a malware in the %appdata%\Microsoft directory. | Our analysis exposed that this is a new variant of a malware dubbed as BADNEWS, which is actively being used in the MONSOON APT campaign. This variant steals documents from USB drives.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Both its capabilities and its code are practically the same as those described by Unit42 in reference to the BadNews threat.
When it first starts, BADNEWS crawls the victim's mapped drives and collects documents with the following extensions: .doc, .docx, .pdf, .ppt, .pptx, and .txt.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
40 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
62 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BADNEWS is a malware family detected in the analysis, but specific details are not provided in the content.
Minor Software changes: BADNEWS
Malware that can download executables and run them via CreateProcess or ShellExecute.
Backdoor that encrypts C2 data using bit rotation and XOR.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.