BADNEWS
MITRE ATT&CK: S0128 View on attack.mitre.org
Aliases: BADNEWS
- First seen
- 2013-11-10 00:00:00
- Malware type
- backdoor, rat
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:41:27
Targeted industries: education-and-nonprofits government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:in country_code:pk
Context
BADNEWS is malware that has been used by the actors responsible for the Patchwork campaign. Its name was given due to its use of RSS feeds, forums, and blogs for command and control.
Detection coverage
- 1 YARA rules
- 368 Sigma rules
Malware & tools used
- Dead Drop Resolver (attack-pattern)
- Web Protocols (attack-pattern)
- Screen Capture (attack-pattern)
- Data from Local System (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- DLL (attack-pattern)
- Data Encoding (attack-pattern)
- Keylogging (attack-pattern)
- Bidirectional Communication (attack-pattern)
- Invalid Code Signature (attack-pattern)
- Automated Collection (attack-pattern)
- Scheduled Task (attack-pattern)
- Data from Network Shared Drive (attack-pattern)
- Standard Encoding (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Data from Removable Media (attack-pattern)
- Windows Command Shell (attack-pattern)
- Process Hollowing (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Native API (attack-pattern)
- Local Data Staging (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Peripheral Device Discovery (attack-pattern)
Used by threat actors
- Patchwork (threat-actor)
Detection rules
- MALPEDIA_Win_Badnews_Auto (yara-rule)
Related threat objects
- Ragnatela (malware)
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- forcepoint.com — Monsoon Analysis Apt Campaign (report)
- Trend Micro — Tech Brief Untangling The Patchwork Cyberespionage Group (report)
- forcepoint.com — Forcepoint Security Labs Monsoon Analysis Report (report)
- ti.qianxin.com — Analysis Of The Attack Activities Of Patchwork Using The Documents Of Relevant Government Agencies In Pakistan As Bait (report)
- researchcenter.paloaltonetworks.com — Unit42 Patchwork Continues Deliver Badnews Indian Subcontinent (report)
- Kaspersky — 101967 (report)
- cocomelonc.github.io — Simple Malware Av Evasion (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Badnews (report)
- blog.fortinet.com — In Depth Look At New Variant Of Monsoon Apt Backdoor Part 2 (report)
- blog.fortinet.com — In Depth Look At New Variant Of Monsoon Apt Backdoor Part 1 (report)
- blog.malwarebytes.com — Patchwork Apt Caught In Its Own Web (report)
- lab52.io — New Patchwork Campaign Against Pakistan (report)
- ti.qianxin.com — Apt C 09 Reappeared As Conflict Intensified Between India And Pakistan (report)
- virusbulletin.com — Vb2019 Lunghihorejsi (report)
- MITRE ATT&CK — S0128 (report)