Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors BadRory

Description

Kaspersky researchers have identified a new APT group named BadRory that has mounted two waves of spear-phishing attacks against Russian organizations. The campaigns took place in October 2022 and April 2023 and leveraged boobytrapped Office emails. Targets included government entities, military contractors, universities, and hospitals.

AI Analysis

· 1 week ago

Executive Summary

BadRory is a suspected APT group observed conducting spear-phishing campaigns against Russian government entities, military contractors, universities, and hospitals through boobytrapped Office documents. The group has demonstrated moderate sophistication, focusing on state-related targets and leveraging phishing as its primary attack vector.

Goals & Targeting

BadRory appears to be targeting sectors critical to national security and societal stability, such as government, military, education, and healthcare. This suggests the group's primary goal may involve intelligence gathering, surveillance, or disruption of state functions. The targeting of Russian entities specifically indicates a potential alignment with Russian interests or internal priorities.

Enhanced Description

BadRory has emerged as a potentially state-sponsored APT group targeting sensitive sectors within Russia. The group has conducted at least two waves of spear-phishing attacks in October 2022 and April 2023, delivering malicious payloads via Office documents. These campaigns suggest BadRory is focused on compromising high-value targets with significant implications for national security. While the group's exact origins remain unclear, its targeting patterns align with common behaviors observed in Russian-speaking APTs. The attacks are likely designed to gather sensitive information or disrupt operations.

Key Capabilities

  • Spear-phishing via Office documents
  • Malware deployment
  • Staging infrastructure

MITRE ATT&CK Tactics

Credential Access
Discovery
Lateral Movement

ATT&CK Techniques

T1566.001 Spear Phishing via Email (Weaponized Document)
T1553 Phishing - Content Isolation

Software / Tooling

Custom Malware

Campaigns & Victims

BadRory's campaigns have demonstrated a methodical approach, with specific targeting of high-value Russian institutions over multiple waves. The group appears to operate with moderate sophistication and demonstrates persistence in achieving its objectives. Notable operations include the 2022 and 2023 spear-phishing campaigns, which targeted a range of sectors including government and military contractors.

IOC Patterns

  • Spear-phishing emails with malicious Office attachments
  • Presence of custom malware payloads

Recommended Actions

  • Enhance email filtering and content isolation for suspected phishing attempts
  • Implement strong endpoint detection and response (EDR) solutions to detect malicious activity

Suggested Tags

APT
Russian-speaking actors
National Security Threat

Confidence Assessment

Confidence in BadRory's APT status is moderate due to the observed campaign patterns and targeting. However, specific details about the group's TTPs, toolset, and exact motivations are limited. Further analysis of sample IOCs would improve understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Healthcare Targeting
Phishing
Government Targeting
Russian-speaking actors
National Security Threat

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.