HALFBAKED

MITRE ATT&CK: S0151 View on attack.mitre.org

First seen
2020-05-10 00:00:00
Malware type
backdoor, trojan
Family
Malware family
Profile updated
2026-07-07 12:45:13

Targeted industries: government-and-public-sector defense-and-aerospace financial-services

Targeted regions: country_code:us country_code:gb

Context

HALFBAKED is a malware family consisting of multiple components intended to establish persistence in victim networks.

Detection coverage

  • 285 Sigma rules

Malware & tools used

  • Process Discovery (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Screen Capture (attack-pattern)
  • PowerShell (attack-pattern)
  • File Deletion (attack-pattern)
  • System Information Discovery (attack-pattern)

Used by threat actors

  • FIN7 (threat-actor)

Reports & references

  • Mandiant — Fin7 Phishing Lnk (report)
  • Mandiant — Cds18 Technical S05 Att&Cking Fin7 (report)
  • malpedia.caad.fkie.fraunhofer.de — Vbs.Halfbaked (report)
  • MITRE ATT&CK — S0151 (report)

External references