BADHATCH
MITRE ATT&CK: S1081 View on attack.mitre.org
Aliases: BADHATCH
- First seen
- 2019-01-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 13:44:29
Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications
Targeted regions: country_code:us country_code:ca country_code:za country_code:pa country_code:it
Context
BADHATCH is a backdoor that has been utilized by FIN8 since at least 2019. BADHATCH has been used to target the insurance, retail, technology, and chemical industries in the United States, Canada, South Africa, Panama, and Italy.
Detection coverage
- 1 YARA rules
- 724 Sigma rules
Malware & tools used
- Reflective Code Loading (attack-pattern)
- PowerShell (attack-pattern)
- Process Injection (attack-pattern)
- Remote System Discovery (attack-pattern)
- Process Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Screen Capture (attack-pattern)
- Embedded Payloads (attack-pattern)
- System Time Discovery (attack-pattern)
- Scheduled Task (attack-pattern)
- Command Obfuscation (attack-pattern)
- Web Protocols (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Proxy (attack-pattern)
- Native API (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Network Service Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Compression (attack-pattern)
- Web Service (attack-pattern)
- File Deletion (attack-pattern)
- Windows Management Instrumentation Event Subscription (attack-pattern)
- Domain Groups (attack-pattern)
- Pass the Hash (attack-pattern)
Used by threat actors
- FIN8 (threat-actor)
Detection rules
- MALPEDIA_Win_Badhatch_Auto (yara-rule)
Reports & references
- Broadcom/Symantec — The Ransomware Threat September 2021 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Badhatch (report)
- bitdefender.com — Bitdefender Pr Whitepaper Badhatch Creat5237 En En (report)
- team-cymru.com — Fin8 Badhatch Threat Indicator Enrichment (report)
- blog.gigamon.com — Abadbabe 8Badf00D Discovering Badhatch And A Detailed Look At Fin8S Tooling (report)
- MITRE ATT&CK — S1081 (report)