Also known as: Win32/Diskcoder.D
Executive Summary
Bad Rabbit is a prominent self‑propagating Windows ransomware that encrypts victims’ files, drops ransom notes, and exfiltrates data to compromised command servers. First notable in Ukraine’s transportation sector, it has since affected numerous organizations worldwide, demanding large cryptocurrency payments. The malware achieves rapid lateral spread via SMB shares and disables security tools by altering registry settings, making containment challenging without timely detection. Key capabilities include file encryption, network scanning for administrative shares, data exfiltration over HTTPS, and disabling of antivirus functions.
Enhanced Description
Bad Rabbit is a Windows‑based, self‑propagating ransomware discovered in early 2018 that rapidly spread across Europe, North America and the Middle East. It typically arrived on victims’ systems via compromised websites or malicious Word documents containing embedded macros, and then deployed a backdoor trojan (badrabbit.exe) which downloaded an encryptor component to conduct the payload. Once executed, Bad Rabbit scans the infected machine for user‑accessible files and encrypts them with an AES‑128 algorithm, appending the custom ".rrp" extension. A ransom note in both English and Russian is dropped in every affected directory, demanding payment in a specified cryptocurrency wallet. In addition to data encryption, the malware exfiltrates selected documents over HTTPS to command‑and‑control servers that use compromised domains, collecting credential information and other forensic clues. The attack’s first major impact was on the Ukrainian transportation sector, where rail operators reported significant service disruptions. Subsequent incidents targeted enterprises ranging from small businesses to large IT vendors, resulting in estimated ransom payments in excess of $50 k per victim. Bad Rabbit shares code similarities with the NotPetya/WhisperGate family but remains a distinct threat capable of rapid lateral movement through SMB and Windows Administrative Shares, as well as disabling antivirus utilities via registry modifications. The combination of self‑replication, powerful encryption routines, and network‑wide scanning makes Bad Rabbit one of the more destructive ransomware campaigns of its era, underscoring the need for strong endpoint protection and vigilant network monitoring.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on publicly documented incidents, reputable security vendor reports (SecureList, ESET, Dragos), and known malware attributes. While core behaviors—self‑propagation, encryption, ransom demand, data exfiltration—are well established, gaps remain regarding the full scope of command‑and‑control infrastructure, specific credential stealing mechanisms, and persistence techniques beyond registry tweaks. Confidence in the identified capabilities is high, though detailed technical chain of execution and all lateral movement vectors may need further verification through internal investigations.
Bad Rabbit is a self-propagating ransomware that affected the Ukrainian transportation sector in 2017. Bad Rabbit has also targeted organizations and consumers in Russia. (Citation: Secure List Bad Rabbit)(Citation: ESET Bad Rabbit)(Citation: Dragos Apr 2019)