BadRory
- First seen
- 2022-10-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:05:20
Targeted industries: government-and-public-sector defense-and-aerospace education-and-nonprofits healthcare-and-pharmaceutical
Targeted regions: country_code:ru
Context
Kaspersky researchers have identified a new APT group named BadRory that has mounted two waves of spear-phishing attacks against Russian organizations. The campaigns took place in October 2022 and April 2023 and leveraged boobytrapped Office emails. Targets included government entities, military contractors, universities, and hospitals.
Reports & references
- Kaspersky — 110752 (report)