BADFLICK

S0642

Malware.View on attack.mitre.org

About this malware

BADFLICK is a backdoor used by Leviathan in spearphishing campaigns first reported in 2018 that targeted the U.S. engineering and maritime industries.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1005
Data from Local System

BADFLICK has uploaded files from victims' machines.

T1016
System Network Configuration Discovery

BADFLICK has captured victim IP address details.

T1082
System Information Discovery

BADFLICK has captured victim computer name, memory space, and CPU details.

T1083
File and Directory Discovery

BADFLICK has searched for files on the infected host.

T1105
Ingress Tool Transfer

BADFLICK has download files from its C2 server.

T1140
Deobfuscate/Decode Files or Information

BADFLICK can decode shellcode using a custom rotating XOR cipher.

T1204.002
Malicious File

BADFLICK has relied upon users clicking on a malicious attachment delivered through spearphishing.

T1497.003
Time Based Checks

BADFLICK has delayed communication to the actor-controlled IP address by 5 minutes.

T1560.002
Archive via Library

BADFLICK has compressed data using the aPLib compression library.

T1566.001
Spearphishing Attachment

BADFLICK has been distributed via spearphishing campaigns containing malicious Microsoft Word documents.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Accenture MUDCARP March 2019 Open source
    Accenture iDefense Unit. (2019, March 5). Mudcarp's Focus on Submarine Technologies. Retrieved August 24, 2021.
  2. FireEye Periscope March 2018 Open source
    FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.