BADCALL is a Lazarus Group malware family associated with North Korean state-sponsored operations and tracked by the U.S. government under the HIDDEN COBRA designation. It has been used to maintain access on compromised networks, relay operator traffic through victim systems, and support follow-on exploitation. Public reporting describes BADCALL primarily as a proxy-capable backdoor family, with Windows and Android variants documented, and later reporting also identifying a Linux ELF variant with similar behavior.
On Windows, BADCALL has been observed as 32-bit executables and DLL implants that function as proxy-server malware. These variants can bind and listen for inbound connections, authenticate operators using hardcoded values, and relay traffic between the victim and remote infrastructure. They use a FakeTLS-style protocol and XOR/ADD-based obfuscation or encryption for command-and-control traffic, including communications over commonly allowed ports such as 443. Some variants modify Windows firewall settings through the Registry to permit inbound access, and at least one loader variant decrypts and deploys an embedded payload, indicating a modular deployment model.
BADCALL also performs host and network reconnaissance. Reported behaviors include collecting the computer name, host name, and network adapter information from compromised systems. These capabilities support operator awareness of the victim environment and facilitate use of the infected host as an internal relay point.
An Android variant of BADCALL has been described as a remote access trojan that listens for incoming connections and supports extensive surveillance and remote-control functions. Reported capabilities include recording phone calls, taking screenshots, reading contacts, transferring files, executing commands, and scanning Wi-Fi channels. This demonstrates that the family spans multiple platforms and is not limited to traditional desktop intrusion sets.
More recent reporting has linked a Linux ELF sample to BADCALL-like behavior, including overlap with Lazarus tradecraft seen in supply-chain activity. This suggests the family or its underlying design patterns have been adapted beyond Windows and Android to support broader operational flexibility.
BADCALL is closely associated with Lazarus operations that rely on proxying, fake-TLS communications, and long-term footholds inside victim environments. It has been referenced alongside other Lazarus malware families such as Bankshot, BLINDINGCAN, AppleJeus, Dtrack, KEYMARBLE, and ThreatNeedle, and has been tied to campaigns spanning espionage and financially motivated activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DHS, FBI, and DoD identified Trojan malware variants used by the North Korean government - referred to by the U.S. Government as BADCALL.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Many entries describe XOR, XOR/ADD, bitwise NOT and XOR, ROR plus XOR, hexadecimal encoding after encryption, and custom encoding/obfuscation of HTTP traffic or beacons.
The traffic to remote systems from this implant are sent and received via the SSL_read and SSL_write APIs available in OpenSSL.
Analysis indicates this application is designed to force a compromised system to function as a proxy server... Analysis of this malware indicates it is designed to turn a victim host into a "hop point" by relaying traffic to a remote system.
"APT41 used a tool called CLASSFON to covertly proxy network communications." / "BADCALL functions as a proxy server between the victim and C2 server." / "Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic..."
The application is also capable of... downloading and uploading data from the compromised Android device.
The fourth file is an Android Package Kit (APK) file designed to run on Android platforms as a fully functioning Remote Access Tool (RAT).
The content is a catalog of malware and threat groups that encrypt command-and-control communications using algorithms such as DES, AES, RC4, XOR, Blowfish, RSA, Camellia, RC2, RC6, and custom ciphers.
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
49 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Badcall is a backdoor malware family used by North Korean threat actors, notably Lazarus, for persistent access and control of compromised systems. The new Linux variant features enhanced logging for operational monitoring and has been linked to infrastructure used in global campaigns.
BADCALL is a malware used by Lazarus Group, notable for having both Windows and Linux versions, and is used in targeted attacks for data exfiltration and espionage.
A Lazarus-linked backdoor. The report analyzes a new Linux variant that daemonizes itself, simulates a kill command via a fake command routine, communicates with C2 infrastructure, and now writes timestamped operational logs to /tmp/sslvpn.log to help operators monitor execution.
Lazarus-associated malware family listed as related malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.