Bad Rabbit
MITRE ATT&CK: S0606 View on attack.mitre.org
Aliases: Win32/Diskcoder.D, BadRabbit, Bad-Rabbit, Bad Rabbit
- First seen
- 2017-10-24 00:00:00
- Malware type
- ransomware, worm
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 40 (36 malicious)
- Last IoC activity
- 2026-09-02 02:41:54
- Profile updated
- 2026-07-07 12:44:51
Targeted industries: transportation-and-logistics media-and-entertainment
Targeted regions: country_code:ua country_code:ru
Context
Bad Rabbit is a self-propagating ransomware that affected the Ukrainian transportation sector in 2017. Bad Rabbit has also targeted organizations and consumers in Russia.
Recent IoC activity
36 malicious indicators in Maltiverse are attributed to Bad Rabbit (S0606). The 20 most recently updated:
Detection coverage
- 1 YARA rules
- 309 Sigma rules
Malware & tools used
- Data Encrypted for Impact (attack-pattern)
- Password Spraying (attack-pattern)
- Firmware Corruption (attack-pattern)
- Service Execution (attack-pattern)
- Scheduled Task (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Drive-by Compromise (attack-pattern)
- LSASS Memory (attack-pattern)
- Bypass User Account Control (attack-pattern)
- Process Discovery (attack-pattern)
- Network Share Discovery (attack-pattern)
- Exploitation of Remote Services (attack-pattern)
- Rundll32 (attack-pattern)
- Malicious File (attack-pattern)
- Native API (attack-pattern)
- Exploitation of Remote Services (attack-pattern)
- Drive-by Compromise (attack-pattern)
- Loss of Productivity and Revenue (attack-pattern)
- User Execution (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
Used by threat actors
- Sandworm Team (threat-actor)
Detection rules
- CAPE_Badrabbit (yara-rule)
Related threat objects
- EternalPetya (malware)
Reports & references
- ESET — Bad Rabbit Not Petya Back (report)
- Cisco Talos — Bad Rabbit (report)
- id-ransomware.blogspot.com — Badrabbit Ransomware (report)
- Kaspersky — 82851 (report)
- intezer.com — Notpetya Returns Bad Rabbit (report)
- MITRE ATT&CK — S0606 (report)
- dragos.com — Implications Of It Ransomware For Ics Environments (report)