BadPatch is a Windows espionage malware family associated with long-running Middle East-focused activity and linked by MITRE to the Gaza Hackers group, also known as Molerats. It functions as a surveillance and collection implant with capabilities centered on victim monitoring, host profiling, document theft, and data exfiltration over HTTP-based command and control.
Observed functionality includes keylogging, screenshot capture, local file collection, and system reconnaissance. BadPatch can capture screenshots in JPG format and exfiltrate them, record keystrokes, collect host metadata such as operating system details, MAC address, and computer name, and search for documents and archives of interest based on extension. Reported targeted file types include common office documents, PDFs, databases, and compressed archives, indicating an emphasis on intelligence collection from user workstations. Collected information may be staged in local log files before exfiltration.
For environmental awareness, BadPatch uses WMI to enumerate installed security products, consistent with security software discovery prior to follow-on actions. For persistence, it establishes a foothold by placing a shortcut to its executable in the Windows Startup folder so it will execute after user logon. Command and control communications have been observed over HTTP, and reporting has also associated the family with command and control of Windows systems over a nonstandard SMTP-related port.
BadPatch has also been linked through shared infrastructure and malware-family overlap to Android espionage activity in the Middle East, including the Welcome Chat operation targeting Arabic-speaking users. That linkage suggests a broader campaign ecosystem operated by the same threat cluster, though BadPatch itself is directly documented here as a Windows malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Welcome Chat espionage app belongs to the very same Android malware family that we identified at the beginning of 2018. That malware used the same C&C server, pal4u.net, as the espionage campaign targeting the Middle East that was identified in late 2017 by Palo Alto Networks and named BadPatch.
The Welcome Chat espionage app belongs to the very same Android malware family that we identified at the beginning of 2018. That malware used the same C&C server, pal4u.net, as the espionage campaign targeting the Middle East that was identified in late 2017 by Palo Alto Networks and named BadPatch.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that persists by placing a link to its executable in the Startup folder.
Malware that gathers selected file types from local systems and stages them for exfiltration.
Backdoor malware that captures JPG screenshots and exfiltrates them.
Malware with keylogging capability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.