BADCALL (Windows)

Malware type
backdoor, rat
Family
Malware family
Profile updated
2026-07-07 14:03:03

Targeted industries: financial-services technology-and-telecommunications

Targeted regions: country_code:kr country_code:jp

Context

BADCALL is a Windows malware family known to function as a remote access tool (RAT) and backdoor. It is associated with targeted attacks against South Korea and Japan, primarily focusing on financial and telecommunications sectors.

Reports & references

  • blog.lexfo.fr — Lexfo Whitepaper The Lazarus Constellation (report)
  • us-cert.gov — Ar19 252A (report)
  • ESET — Linux Malware Strengthens Links Lazarus 3Cx Supply Chain Attack (report)
  • brandefense.io — Lazarus Apt Group Apt38 (report)
  • cocomelonc.github.io — Simple Malware Av Evasion (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Badcall (report)
  • us-cert.gov — Mar 10135536 B White (report)

External references