BADHATCH

MITRE ATT&CK: S1081 View on attack.mitre.org

Aliases: BADHATCH

First seen
2019-01-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:44:29

Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications

Targeted regions: country_code:us country_code:ca country_code:za country_code:pa country_code:it

Context

BADHATCH is a backdoor that has been utilized by FIN8 since at least 2019. BADHATCH has been used to target the insurance, retail, technology, and chemical industries in the United States, Canada, South Africa, Panama, and Italy.

Detection coverage

  • 1 YARA rules
  • 724 Sigma rules

Malware & tools used

  • Reflective Code Loading (attack-pattern)
  • PowerShell (attack-pattern)
  • Process Injection (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Process Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Screen Capture (attack-pattern)
  • Embedded Payloads (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • Web Protocols (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Proxy (attack-pattern)
  • Native API (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Compression (attack-pattern)
  • Web Service (attack-pattern)
  • File Deletion (attack-pattern)
  • Windows Management Instrumentation Event Subscription (attack-pattern)
  • Domain Groups (attack-pattern)
  • Pass the Hash (attack-pattern)

Used by threat actors

  • FIN8 (threat-actor)

Detection rules

  • MALPEDIA_Win_Badhatch_Auto (yara-rule)

Reports & references

  • Broadcom/Symantec — The Ransomware Threat September 2021 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Badhatch (report)
  • bitdefender.com — Bitdefender Pr Whitepaper Badhatch Creat5237 En En (report)
  • team-cymru.com — Fin8 Badhatch Threat Indicator Enrichment (report)
  • blog.gigamon.com — Abadbabe 8Badf00D Discovering Badhatch And A Detailed Look At Fin8S Tooling (report)
  • MITRE ATT&CK — S1081 (report)

External references