BadPatch

S0337

Malware.View on attack.mitre.org

About this malware

BadPatch is a Windows Trojan that was used in a Gaza Hackers-linked campaign.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1005
Data from Local System

BadPatch collects files from the local system that have the following extensions, then prepares them for exfiltration: .xls, .xlsx, .pdf, .mdb, .rar, .zip, .doc, .docx.

T1056.001
Keylogging

BadPatch has a keylogging capability.

T1071.001
Web Protocols

BadPatch uses HTTP for C2.

T1071.003
Mail Protocols

BadPatch uses SMTP for C2.

T1074.001
Local Data Staging

BadPatch stores collected data in log files before exfiltration.

T1082
System Information Discovery

BadPatch collects the OS system, OS version, MAC address, and the computer name from the victim’s machine.

T1083
File and Directory Discovery

BadPatch searches for files with specific file extensions.

T1105
Ingress Tool Transfer

BadPatch can download and execute or update malware.

T1113
Screen Capture

BadPatch captures screenshots in .jpg format and then exfiltrates them.

T1497.001
System Checks

BadPatch attempts to detect if it is being run in a Virtual Machine (VM) using a WMI query for disk drive name, BIOS, and motherboard information.

T1518.001
Security Software Discovery

BadPatch uses WMI to enumerate installed security products in the victim’s environment.

T1547.001
Registry Run Keys / Startup Folder

BadPatch establishes a foothold by adding a link to the malware executable in the startup folder.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Unit 42 BadPatch Oct 2017 Open source
    Bar, T., Conant, S. (2017, October 20). BadPatch. Retrieved November 13, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.