BadRory

First seen
2022-10-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Actor type
nation-state
Profile updated
2026-07-07 12:05:20

Targeted industries: government-and-public-sector defense-and-aerospace education-and-nonprofits healthcare-and-pharmaceutical

Targeted regions: country_code:ru

Context

Kaspersky researchers have identified a new APT group named BadRory that has mounted two waves of spear-phishing attacks against Russian organizations. The campaigns took place in October 2022 and April 2023 and leveraged boobytrapped Office emails. Targets included government entities, military contractors, universities, and hospitals.

Reports & references

  • Kaspersky — 110752 (report)

External references