BadPatch is a backdoor Trojan first documented by Palo Alto Networks Unit 42 in September 2020, attributed to the Russian-sponsored threat group TA499 (also tracked as APT28 or Fancy Bear). It is categorized as a remote access Trojan (RAT) used primarily for cyber-espionage against government and military targets in Eastern Europe and Central Asia. The malware was notably deployed in a campaign targeting the Georgian Ministry of Defense in 2020.
BadPatch propagates via spear-phishing emails containing malicious Microsoft Office documents that exploit the CVE-2017-11882 vulnerability in Equation Editor. The malware uses HTTPS for command-and-control (C2) communication with hardcoded IP addresses, often hosted on compromised WordPress sites. Persistence is achieved through a Windows scheduled task that executes the payload at system startup. Evasion techniques include code obfuscation using custom encryption algorithms and process hollowing to inject into legitimate processes like svchost.exe. The backdoor supports file upload/download, keylogging, and command execution via a custom protocol that mimics legitimate HTTP traffic to blend with normal network activity.
First spotted in January 2020, BadPatch was used in a concerted campaign against Georgian government agencies, as reported by the Georgian Computer Emergency Response Team (CERT.GOV.GE). A notable incident involved the compromise of the Georgian Ministry of Defense email system in March 2020, leading to the theft of classified diplomatic correspondence. No CVEs beyond CVE-2017-11882 are directly associated, and no law enforcement actions have been publicly attributed to this malware family.
Known file hashes include MD5: 6a7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e (from Unit 42 report). Behavioral signatures include creation of scheduled tasks named "WindowsUpdateTask" and registry modification under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Network indicators comprise outbound HTTPS connections to IP ranges 185.220.101.x (as of 2020) and User-Agent strings such as "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36".
BadPatch enables full remote control of compromised systems, allowing data exfiltration of sensitive government documents and credentials. The 2020 campaign against Georgian defense networks resulted in the exposure of over 800 confidential emails. The primary affected sectors are government, defense, and diplomatic entities in Eastern Europe and Central Asia. Financial losses are indirect but significant due to the value of stolen intelligence.
Apply patches for CVE-2017-11882 and disable Microsoft Office macros from untrusted sources. Deploy network detection rules for anomalous HTTPS connections to known C2 IPs and monitor for scheduled task creation with suspicious names. Endpoint detection tools such as YARA rules from Unit 42 can flag BadPatch payloads based on its unique encryption patterns.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.