BADFLICK

Malware updated 4 months ago (2024-05-04T19:55:58.612Z)
Download STIX
Preview STIX
Badflick is a malware that belongs to the family of backdoors and is commonly used by APT40, a Chinese threat group. This malware can modify the file system, generate a reverse shell, and change its command-and-control configuration. Badflick is usually deployed through custom credential theft utilities like HOMEFRY, a password dumper/cracker, which has previously been used in conjunction with AIRBREAK and BADFLICK backdoors. APT40 has also been known to use other malware such as PHOTO and CHINA CHOPPER. PHOTO, also known as Derusbi, is a commercially available backdoor that has been observed being used by APT40. Additionally, APT40 leverages tools such as MURKYTOP, a command-line reconnaissance tool, to gather information about compromised systems. Historical indicators show that APT40 has been using these tools and techniques for several years. For example, green.ddd, a file hash associated with AIRBREAK, has been observed in previous attacks by APT40. The use of sophisticated malware like Badflick and custom-built tools highlights the advanced capabilities of APT40 and underscores the importance of strong cybersecurity measures.
Description last updated: 2023-06-23T15:48:34.098Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the BADFLICK Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
MITRE
2 years ago
Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries | Mandiant
MITRE
2 years ago
APT40: Examining a China-Nexus Espionage Actor | Mandiant