Kaspersky researchers have identified a new APT group named BadRory that has mounted two waves of spear-phishing attacks against Russian organizations. The campaigns took place in October 2022 and April 2023 and leveraged boobytrapped Office emails. Targets included government entities, military contractors, universities, and hospitals.
Executive Summary
BadRory is a suspected APT group observed conducting spear-phishing campaigns against Russian government entities, military contractors, universities, and hospitals through boobytrapped Office documents. The group has demonstrated moderate sophistication, focusing on state-related targets and leveraging phishing as its primary attack vector.
Goals & Targeting
BadRory appears to be targeting sectors critical to national security and societal stability, such as government, military, education, and healthcare. This suggests the group's primary goal may involve intelligence gathering, surveillance, or disruption of state functions. The targeting of Russian entities specifically indicates a potential alignment with Russian interests or internal priorities.
Enhanced Description
BadRory has emerged as a potentially state-sponsored APT group targeting sensitive sectors within Russia. The group has conducted at least two waves of spear-phishing attacks in October 2022 and April 2023, delivering malicious payloads via Office documents. These campaigns suggest BadRory is focused on compromising high-value targets with significant implications for national security. While the group's exact origins remain unclear, its targeting patterns align with common behaviors observed in Russian-speaking APTs. The attacks are likely designed to gather sensitive information or disrupt operations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
BadRory's campaigns have demonstrated a methodical approach, with specific targeting of high-value Russian institutions over multiple waves. The group appears to operate with moderate sophistication and demonstrates persistence in achieving its objectives. Notable operations include the 2022 and 2023 spear-phishing campaigns, which targeted a range of sectors including government and military contractors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in BadRory's APT status is moderate due to the observed campaign patterns and targeting. However, specific details about the group's TTPs, toolset, and exact motivations are limited. Further analysis of sample IOCs would improve understanding.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics