Bad Rabbit is ransomware, also referred to as Diskcoder/Win32_DiskcoderD, that spread in 2017 across Russia, Ukraine, and other Eastern European countries, with additional reports from countries including Turkey, Germany, Bulgaria, Poland, South Korea, and later the United States. Confirmed or reported victims included Russian media outlets such as Interfax and Fontanka.ru, as well as Ukrainian organizations and infrastructure including Odessa airport, the Kiev subway/metro, and the Ministry of Infrastructure of Ukraine. Researchers assessed it as a targeted attack against corporate networks.
Initial infection was carried out through user execution of a fake Adobe Flash installer, commonly named install_flash_player.exe, and through watering-hole activity on compromised popular websites where JavaScript was injected into HTML pages or .js files. Reporting also linked early infections to compromised Russian media sites, including argumentiru.com. After execution, Bad Rabbit used rundll32 to launch a malicious DLL stored as C:\Windows\infpub.dat. The infpub.dat component created a scheduled task to launch the malicious executable and attempted to bypass UAC to obtain elevated administrative privileges.
For propagation and post-compromise activity, Bad Rabbit used Mimikatz to harvest credentials from victim machines, used NTLM login credentials to brute force Windows machines, and used the EternalRomance SMB exploit to spread through victim networks. It encrypted files and disks using AES-128-CBC and RSA-2048, then directed victims to a Tor-hidden payment site demanding 0.05 Bitcoin for decryption, with reporting noting the price increased after roughly 40 hours. The ransom note used red text on a black background and was described as similar to NotPetya/Petya-related messaging.
The malware was widely noted as bearing similarities to Petya and NotPetya in both appearance and methods, though reporting stated researchers could not confirm it was directly related. Unlike NotPetya, the content states Bad Rabbit did not appear to be a wiper and reportedly decrypted the hard drive when the correct password was entered. Some reporting noted pop-culture references in the code, including Game of Thrones-related names used for scheduled tasks, and a password list containing strings such as "love," "sex," "god," and "secret." Attribution to Russia was discussed in commentary, particularly in the context of attacks on Ukrainian companies, but the content states no official accusation had been made.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Dillon has crafted his modified exploits to take advantage of the following vulnerabilities: CVE-2017-0143 Type confusion between WriteAndX and Transaction requests EternalRomance EternalSynergy
Bad Rabbit used the EternalRomance SMB exploit to spread through victim networks.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
the malware’s code is peppered with pop culture references including the names of two dragons from Game of Thrones and the character Gray Worm used as names for scheduled tasks.
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
The content repeatedly describes victims being lured into opening malicious attachments, enabling macros, launching installers, clicking embedded files/links, or otherwise directly executing malicious content.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
the malware’s code is peppered with pop culture references including the names of two dragons from Game of Thrones and the character Gray Worm used as names for scheduled tasks.
the malware’s code is peppered with pop culture references including the names of two dragons from Game of Thrones and the character Gray Worm used as names for scheduled tasks.
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
Bad Rabbit has masqueraded as a Flash Player installer through the executable file install_flash_player.exe.
Akira has used legitimate names and locations for files to evade defenses.
32 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Enterprise New Software: ... Bad Rabbit
Ransomware that uses a scheduled task to launch its malicious executable.
Ransomware executed when users install an executable disguised as a Flash installer.
Ransomware mentioned as one of several cyber-attacks affecting Ukraine.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.