Bad Rabbit

MITRE ATT&CK: S0606 View on attack.mitre.org

Aliases: Win32/Diskcoder.D, BadRabbit, Bad-Rabbit, Bad Rabbit

First seen
2017-10-24 00:00:00
Malware type
ransomware, worm
Family
Malware family
Operating systems
windows
Related IoCs
40 (36 malicious)
Last IoC activity
2026-09-02 02:41:54
Profile updated
2026-07-07 12:44:51

Targeted industries: transportation-and-logistics media-and-entertainment

Targeted regions: country_code:ua country_code:ru

Context

Bad Rabbit is a self-propagating ransomware that affected the Ukrainian transportation sector in 2017. Bad Rabbit has also targeted organizations and consumers in Russia.

Recent IoC activity

36 malicious indicators in Maltiverse are attributed to Bad Rabbit (S0606). The 20 most recently updated:

TypeIndicatorUpdatedSources
URL https://github.com/Okafor-twd/AWP-UI/releases/tag/release 2026-09-02 1
URL https://github.com/Endermanch/MalwareDatabase/blob/master/ransomwares/BadRabbit.zip 2026-09-02 1
file sample [email protected] 2026-08-29 5
file sample malwaredatabase 2026-08-28 1
file sample Nuovo Documento di testo.txt 2026-08-24 1
URL https://github.com/Da2dalus/The-MALWARE-Repo 2026-08-23 1
file sample download (5).jpg 2026-08-21 1
file sample FATALITY.exe 2026-08-11 1
file sample Rf menu installerV 2.1.zip 2026-08-06 1
file sample tiktok_live_studio_downloader-v0.0.1-wid-97c1aDZO62u (1).exe 2026-08-05 2
file sample sample 2026-07-31 1
file sample VoicemodInstaller_1.6.20-eoedt1.exe 2026-07-28 2
URL https://github.com/Da2dalus/The-MALWARE-Repo/blob/master/Ransomware/BadRabbit.exe 2026-07-27 1
file sample Ransomware 2026-07-26 1
file sample Urget Contract Action.zip 2026-07-22 2
file sample tmpog90g30g 2026-07-15 1
file sample Captura de pantalla 2026-07-10 180505.png 2026-07-14 1
file sample uninstall.exe 2026-07-10 1
file sample Urget Contract Action.eml 2026-07-02 2
URL https://github.com/Itzsten/Malware-Respository/blob/main/42.zip 2026-07-01 1

Detection coverage

  • 1 YARA rules
  • 309 Sigma rules

Malware & tools used

  • Data Encrypted for Impact (attack-pattern)
  • Password Spraying (attack-pattern)
  • Firmware Corruption (attack-pattern)
  • Service Execution (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • Process Discovery (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • Exploitation of Remote Services (attack-pattern)
  • Rundll32 (attack-pattern)
  • Malicious File (attack-pattern)
  • Native API (attack-pattern)
  • Exploitation of Remote Services (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • Loss of Productivity and Revenue (attack-pattern)
  • User Execution (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)

Used by threat actors

Detection rules

  • CAPE_Badrabbit (yara-rule)

Related threat objects

Reports & references

  • ESET — Bad Rabbit Not Petya Back (report)
  • Cisco Talos — Bad Rabbit (report)
  • id-ransomware.blogspot.com — Badrabbit Ransomware (report)
  • Kaspersky — 82851 (report)
  • intezer.com — Notpetya Returns Bad Rabbit (report)
  • MITRE ATT&CK — S0606 (report)
  • dragos.com — Implications Of It Ransomware For Ics Environments (report)

External references