Description
BADHATCH is a backdoor that the FIN8 threat actor has used since at least 2019 against the insurance, retail, technology, and chemical industries in the United States, Canada, South Africa, Panama, and Italy.
Stats
- First seen
- May 2022
- Last seen
- September 2026
MITRE ATT&CK techniques
35 techniques across 8 tactics.
TA0002 Execution
TA0004 Privilege Escalation
TA0005 Stealth
TA0007 Discovery
- T1018Remote System Discovery
- T1033System Owner/User Discovery
- T1046Network Service Discovery
- T1049System Network Connections Discovery
- T1057Process Discovery
- T1069Permission Groups Discovery
- T1069.002Domain Groups
- T1082System Information Discovery
- T1124System Time Discovery
- T1135Network Share Discovery
- T1482Domain Trust Discovery
TA0009 Collection
- T1113Screen Capture
TA0011 Command and Control
TA0010 Exfiltration
- T1041Exfiltration Over C2 Channel
Associated groups
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Backdoor.Badhatch |