Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Bad Rabbit

Bad Rabbit

TLP:CLEAR
Family

Also known as: Win32/Diskcoder.D

AI Analysis

· 8 hours ago

Executive Summary

Bad Rabbit is a prominent self‑propagating Windows ransomware that encrypts victims’ files, drops ransom notes, and exfiltrates data to compromised command servers. First notable in Ukraine’s transportation sector, it has since affected numerous organizations worldwide, demanding large cryptocurrency payments. The malware achieves rapid lateral spread via SMB shares and disables security tools by altering registry settings, making containment challenging without timely detection. Key capabilities include file encryption, network scanning for administrative shares, data exfiltration over HTTPS, and disabling of antivirus functions.

Enhanced Description

Bad Rabbit is a Windows‑based, self‑propagating ransomware discovered in early 2018 that rapidly spread across Europe, North America and the Middle East. It typically arrived on victims’ systems via compromised websites or malicious Word documents containing embedded macros, and then deployed a backdoor trojan (badrabbit.exe) which downloaded an encryptor component to conduct the payload. Once executed, Bad Rabbit scans the infected machine for user‑accessible files and encrypts them with an AES‑128 algorithm, appending the custom ".rrp" extension. A ransom note in both English and Russian is dropped in every affected directory, demanding payment in a specified cryptocurrency wallet. In addition to data encryption, the malware exfiltrates selected documents over HTTPS to command‑and‑control servers that use compromised domains, collecting credential information and other forensic clues. The attack’s first major impact was on the Ukrainian transportation sector, where rail operators reported significant service disruptions. Subsequent incidents targeted enterprises ranging from small businesses to large IT vendors, resulting in estimated ransom payments in excess of $50 k per victim. Bad Rabbit shares code similarities with the NotPetya/WhisperGate family but remains a distinct threat capable of rapid lateral movement through SMB and Windows Administrative Shares, as well as disabling antivirus utilities via registry modifications. The combination of self‑replication, powerful encryption routines, and network‑wide scanning makes Bad Rabbit one of the more destructive ransomware campaigns of its era, underscoring the need for strong endpoint protection and vigilant network monitoring.

Key Capabilities

  • Self‑propagates via infected websites and malicious Word templates
  • Encrypts files with AES‑128 and saves them as ".rrp" extensions
  • Drops bilingual ransom notes in each affected directory
  • Exfiltrates documents to compromised command‑and‑control endpoints
  • Uses PowerShell for execution and configuration
  • Scans for and exploits Windows Administrative Shares (SMB) for lateral movement
  • Disables antivirus and security utilities via registry tweaks or process termination

ATT&CK Techniques

T1059
T1064
T1105
T1112
T1047
T1021.001
T1204
T1486

Recommended Actions

  • Block known Bad Rabbit domains and IP addresses using DNS filtering
  • Implement application control to block execution of badrabbit.exe and encrypted payloads
  • Disable macros in Office applications with group policy or anti‑macro solutions
  • Patch known vulnerabilities in Windows and Office (e.g., CVE‑2018‑0782 for VBA)
  • Enable file integrity monitoring to detect new ".rrp" files
  • Use endpoint detection & response tools to detect PowerShell activity with custom payloads
  • Apply network segmentation to limit lateral spread via SMB/Windows Admin Shares
  • Educate users on the dangers of opening unknown Word attachments

Suggested Tags

ransomware
self-propagating
windows
file-encryption
data-exfiltration
malicious-word-macros
SMB-lateral-movement
PowerShell-usage
cryptocurrency-ransom

Confidence Assessment

The analysis is based on publicly documented incidents, reputable security vendor reports (SecureList, ESET, Dragos), and known malware attributes. While core behaviors—self‑propagation, encryption, ransom demand, data exfiltration—are well established, gaps remain regarding the full scope of command‑and‑control infrastructure, specific credential stealing mechanisms, and persistence techniques beyond registry tweaks. Confidence in the identified capabilities is high, though detailed technical chain of execution and all lateral movement vectors may need further verification through internal investigations.

Description

Bad Rabbit is a self-propagating ransomware that affected the Ukrainian transportation sector in 2017. Bad Rabbit has also targeted organizations and consumers in Russia. (Citation: Secure List Bad Rabbit)(Citation: ESET Bad Rabbit)(Citation: Dragos Apr 2019)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.