BADFLICK is a Windows backdoor associated with the China-linked espionage group APT40, also tracked as Leviathan and GreenCrash. It has been observed as one of the group’s frequently used backdoors in intrusions targeting government, academic, research, maritime, and other strategic sectors aligned with APT40 collection priorities. BADFLICK has been delivered through spearphishing campaigns, including malicious Microsoft Word attachments that rely on user execution.
Functionally, BADFLICK supports remote access and post-compromise collection. Reported capabilities include generating a reverse shell, downloading files from command-and-control infrastructure, uploading files from victim systems, and searching the infected host for files of interest. It also performs host and network reconnaissance by collecting details such as the victim computer name, processor and memory information, and IP address information. BADFLICK has also been documented decoding shellcode with a custom rotating XOR routine and delaying outbound communication for several minutes, behavior consistent with defense evasion and staged execution.
Within APT40 operations, BADFLICK has been used alongside other malware and tooling to help establish footholds and support broader intrusion activity. Its observed tradecraft is consistent with espionage-oriented backdoors used for interactive access, victim profiling, file collection, and follow-on tasking on compromised Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
PHOTO, BADFLICK, and CHINA CHOPPER are among the most frequently observed backdoors used by APT40.
PHOTO, BADFLICK, and CHINA CHOPPER are among the most frequently observed backdoors used by APT40.
PHOTO, BADFLICK, and CHINA CHOPPER are among the most frequently observed backdoors used by APT40.
PHOTO, BADFLICK, and CHINA CHOPPER are among the most frequently observed backdoors used by APT40.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT40 has used a combination of tool frameworks and malware to establish persistence, escalate privileges, map, and move laterally on victim networks. ... BADFLICK/Greencrash
16 distinct techniques documented for this family, organized by ATT&CK tactic.
has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails... has required user execution of a malicious MSI installer... has been executed through user installation of an executable disguised as a flash installer.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Captures victim IP address details.
Enterprise New Software: ... BADFLICK
Malware that decodes shellcode with a custom rotating XOR cipher.
Malware capable of uploading files from victim machines.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.