HALFBAKED is a Windows malware family associated with FIN7 and used as a backdoor to establish and maintain a foothold in victim environments. It has been observed in financially motivated intrusion activity targeting sectors such as hospitality, retail, restaurants, and financial services. FIN7 has delivered HALFBAKED through spearphishing campaigns that used socially engineered document lures and script-based infection chains involving VBScript, JavaScript, and PowerShell.
HALFBAKED supports interactive post-compromise operations including host profiling, process discovery, screenshot capture, execution of PowerShell scripts, and deletion of specified files. Reported command functionality includes collecting operating system, processor, BIOS, and running process information, as well as executing additional scripts or binaries under operator control. It also uses WMI queries for system information gathering. The malware has been described as part of a multi-component toolkit intended to establish persistence in contested networks and maintain command-and-control communications through implant beaconing.
Observed FIN7 tradecraft around HALFBAKED includes staged script launchers, scheduled-task-based persistence, and follow-on payload execution after user interaction with phishing lures. In documented operations, HALFBAKED functioned as a backdoor within a broader intrusion chain that also leveraged obfuscated PowerShell and additional tooling for access maintenance and operator tasking.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware capable of executing PowerShell scripts.
Backdoor malware that can delete specified files.
Malware capable of executing PowerShell scripts.
Backdoor malware that obtains information about running processes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.