Bad Rabbit is Windows ransomware active in October 2017 that primarily affected organizations in Russia and Eastern Europe, including transportation, media, financial, and infrastructure entities. Initial access was achieved through compromised websites presenting a fraudulent Adobe Flash Player update, requiring victim interaction to execute the installer. The malware encrypts files and disk contents using DiskCryptor-related components, modifies the master boot record to present a ransom demand at boot, and schedules a reboot.
Bad Rabbit spreads laterally over Windows networks using SMB, WMI, PsExec, stolen credentials, and password brute forcing. It incorporates credential-theft tooling resembling Mimikatz and uses the EternalRomance MS17-010 exploit for additional propagation. Analysis found a shared core codebase and highly similar build tooling with Nyetya/NotPetya, although common authorship was not established solely by those similarities. The UK government has publicly attributed the Bad Rabbit operation to the Russian GRU cyber program commonly tracked as Sandworm, TeleBots, BlackEnergy Group, or VoodooBear.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Cisco Talos was alerted to a widescale ransomware campaign affecting organizations across eastern Europe and Russia... the dropper contains the BadRabbit ransomware. Once installed there is an SMB component used for lateral movement and further infection.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
They used “social engineering by sending a malicious executable application, from the ‘Locky’ or ‘BadRabbit’ (computer virus) families, hidden in an e-mail...”
The attack using the BadRabbit family in October 2017.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Talos assesses with high confidence that a fake Flash Player update is being delivered via a drive-by-download and compromising systems.
They used “social engineering by sending a malicious executable application, from the ‘Locky’ or ‘BadRabbit’ (computer virus) families, hidden in an e-mail and in the form of a file that apparently would come from other government institutions, regarding the threat of COVID-19.”
They used “social engineering by sending a malicious executable application, from the ‘Locky’ or ‘BadRabbit’ (computer virus) families, hidden in an e-mail and in the form of a file that apparently would come from other government institutions, regarding the threat of COVID-19.”
It is performed by Microsoft Windows legitimate features, via: ... WMI
The malware then creates a scheduled task with the parameters shown in the screenshot below... the malware creates a second scheduled task that is responsible for rebooting the system.
The dropper ... requires a user to facilitate the infection and does not use any exploit to compromise the system directly.
That subtly powerful hacking tool was designed to siphon a Windows user's password out of the ephemeral murk of a computer's memory, so that it could be used to gain repeated access to that computer, or to any others that victim's account could access on the same network.
It is performed by Microsoft Windows legitimate features, via: SVCCTL: the remote service management
a new variant of that code locks up hundreds of machines and handicaps infrastructure
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an example of a black-swan ransomware event.
Referenced as a targeted ransomware family with technique similarities to OlympicDestroyer.
Ransomware family referenced as one of the malicious payloads used in phishing-style delivery disguised as government COVID-19 communications.
Wiper malware with ransomware-like features, used to disrupt organizations, particularly in industrial and critical infrastructure sectors.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.