Macintosh HD:Users:Shared:dd:4work:Bitdefender-PR-Whitepaper-BADHATCH-creat5237-en_EN:Bitdefender-PR-Whitepaper-BADHATCH-creat5237-en_EN.indd
ID: 63e3b2a1-eeb3-4919-a93f-f6a98a29e8f2
STIX ID: report--63e3b2a1-eeb3-4919-a93f-f6a98a29e8f2
Threat Score
80/100
Uploaded: 2026-08-14
Published Date: 2021-03-10
Last Modified Date: 2021-03-10
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FIN8's BADHATCH backdoor analysis: Bitdefender describes the evolution and technical details of BADHATCH (v2.12–v2.14), including malicious PowerShell deployment, in-memory .NET payload loading, persistence via WMI event subscriptions, token impersonation and process injection, credential dumping and lateral movement, command-and-control protocol masquerading as legitimate Windows Update traffic, lists of IOCs (IPs, URLs, sample hashes), affected sectors and recommended mitigations.
