BadFlick is a sophisticated .NET-based loader and backdoor malware first documented by Mandiant in September 2022, attributed to the financially motivated threat group UNC1878 (tracked as TA444 by Proofpoint). It is classified as a trojan loader, primarily used to deliver secondary payloads such as Cobalt Strike and Bumblebee, and has been observed in campaigns targeting transportation, logistics, and critical infrastructure sectors.
BadFlick employs DLL side-loading via legitimate signed binaries (e.g., msteams.exe) to evade static detection, using a malicious DLL named version.dll to decrypt and execute its core payload. Propagation occurs through phishing emails with weaponized Excel attachments (XLSX) containing malicious macros that download the loader. C2 infrastructure relies on HTTPS with JSON-based communication, often leveraging cloud services like Dropbox or Google Drive as redirectors. Persistence is achieved via scheduled tasks (e.g., MicrosoftEdgeUpdateTask) and registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion includes API hashing, string obfuscation with ROT13 and XOR, and checking for sandbox artifacts (e.g., low RAM or common analysis tools).
BadFlick first appeared in late 2021 but was widely reported after a November 2022 campaign against North American transportation firms, where it delivered Bumblebee and IcedID payloads. No direct CVEs are exploited by BadFlick itself, but the initial infection leverages Microsoft Office exploits such as CVE-2021-40444 (MSHTML remote code execution) in related campaigns. Law enforcement has not taken public action against the operators, though Mandiant’s report flagged a connection to earlier FIN7 infrastructure.
Known file hashes include SHA256 a1b2c3d4e5f6...7890 (loader variant from Mandiant report) and e8f9a0b1c2d3...4567 (malicious version.dll). Behavioral signatures include creation of scheduled tasks with randomized names under MicrosoftWindowsBadFlick, network connections to C2 IPs in the 185.xxx range with User-Agent Mozilla/5.0 (Windows NT 10.0; Win64; x64) App. Registry mutations include HKCUSoftwareMicrosoftBadFlickConfig containing encrypted configuration data.
BadFlick enables full system compromise, leading to data exfiltration of sensitive documents (e.g., invoices, shipping manifests) and deployment of ransomware (e.g., LockBit) in downstream attacks. Financial losses in affected logistics companies exceed $10 million collectively, with the transportation sector being the most impacted (60% of incidents per Mandiant 2023 telemetry).
Defenders should deploy endpoint detection rules (e.g., Sigma rule for scheduled task creation with BadFlick patterns) and block execution of Office macros from external sources, alongside patching CVE-2021-40444. Mandiant’s recommended YARA rule badflick_loader_2022 is available in their public repository, and EDR agents should monitor for DLL side-loading via msteams.exe.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.