logo

Macintosh HD:Users:Shared:dd:4work:Bitdefender-PR-Whitepaper-BADHATCH-creat5237-en_EN:Bitdefender-PR-Whitepaper-BADHATCH-creat5237-en_EN.indd

ID: 63e3b2a1-eeb3-4919-a93f-f6a98a29e8f2

STIX ID: report--63e3b2a1-eeb3-4919-a93f-f6a98a29e8f2

Threat Score

80/100

Uploaded: 2026-08-14

Published Date: 2021-03-10

Last Modified Date: 2021-03-10

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FIN8's BADHATCH backdoor analysis: Bitdefender describes the evolution and technical details of BADHATCH (v2.12–v2.14), including malicious PowerShell deployment, in-memory .NET payload loading, persistence via WMI event subscriptions, token impersonation and process injection, credential dumping and lateral movement, command-and-control protocol masquerading as legitimate Windows Update traffic, lists of IOCs (IPs, URLs, sample hashes), affected sectors and recommended mitigations.