FortiGuard Labs detailed a MONSOON APT campaign that used malicious RTF files exploiting CVE-2015-1641 to deliver a new BADNEWS backdoor variant. One lure, "Senate_panel.doc", displayed a Pakistan-themed decoy while embedded multi-stage shellcode installed persistence through the Windows Run registry key and launched a malicious jli.dll via DLL side-loading with a renamed signed Java executable. Researchers linked additional lures tied to Pakistan-India conflict themes and UN job content to the same malware family, which supports keylogging, screenshots, file transfer, remote shell access, and theft of documents from USB and other drives.
The malware relied on web-based command-and-control techniques designed to blend into normal traffic, retrieving encrypted C2 information from legitimate services including GitHub, WordPress, RSS feeds, forums, blogs, and Dynamic DNS infrastructure. FortiGuard said exploit documents referenced compromised websites through INCLUDEPICTURE fields, and one site, justfood.pk, appeared to serve the decoy file and had previously been defaced by a persona calling itself R00T D3STR0Y3R, though the researchers did not make a definitive attribution. MITRE ATT&CK documentation and later industry reporting describe BADNEWS as using HTTP-based dead-drop resolvers, registry and scheduled-task persistence, DLL side-loading, and broad document collection and staging for exfiltration, underscoring the backdoor's continued use in South Asia-focused intrusion activity.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks Unit 42 published research stating that Patchwork continued delivering BADNEWS in operations targeting the Indian subcontinent, marking a later public reporting milestone for the malware's use.
FortiGuard Labs published a follow-up analysis of the MONSOON BADNEWS variant, detailing exploit documents' external URL references, the apparent use of compromised websites including justfood.pk, and campaign indicators such as C2 domains and hashes.
FortiGuard Labs published technical analysis of the "Senate_panel.doc" RTF lure, describing its CVE-2015-1641 exploitation chain, Pakistan-themed decoy document, DLL side-loading, persistence, and BADNEWS capabilities including keylogging and USB document theft.
FortiGuard said the malicious RTF exploit file associated with the MONSOON campaign was uploaded to VirusTotal under the name "Senate_panel.doc." The sample exploited CVE-2015-1641 and was tied to delivery of a BADNEWS variant.
FortiGuard reported that the website justfood.pk had been hacked and defaced by the persona R00T D3STR0Y3R no later than 2017-02-09. The researchers suggested this may indicate the site was under attacker control before it was later referenced in MONSOON exploit activity.
MITRE ATT&CK published an entry for BADNEWS (S0128), documenting it as a backdoor malware family and describing its command-and-control, persistence, collection, and execution behaviors.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 32 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
researchcenter.paloaltonetworks.com
Open sourceblog.fortinet.com
Open sourceblog.fortinet.com
Open sourceattack.mitre.org
Open sourceforcepoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.