BadPaw

Malware

⚠️ Overview

BadPaw is a sophisticated backdoor trojan first documented in mid-2022 by the QiAnXin Threat Intelligence Center, attributed to the advanced persistent threat group APT-C-36 (Blind Eagle) operating out of Colombia. It is classified as a multi-stage remote access trojan (RAT) used primarily for espionage and data exfiltration against government and financial sector targets in Latin America.

🔧 Technical Capabilities

BadPaw employs a multi-stage infection chain beginning with spear-phishing emails containing Microsoft Office documents that exploit the CVE-2021-40444 MSHTML remote code execution vulnerability to drop the first-stage loader. The malware uses encrypted HTTP/HTTPS communication with its command-and-control (C2) servers, with traffic disguised as legitimate API calls to cloud services such as OneDrive and Dropbox for stealth. Persistence is achieved via scheduled tasks and registry Run keys, while DLL side-loading of legitimate signed binaries (e.g., mscoree.dll) evades signature-based detection. The backdoor supports keylogging, screen capture, file upload/download, and process manipulation, employing AES-256 encryption for C2 payloads and spawning encrypted PowerShell scripts to bypass application whitelisting.

📜 History & Notable Incidents

The first known campaign using BadPaw was detected in June 2022 targeting the Colombian Ministry of Health and multiple banking institutions in Ecuador and Chile. In November 2022, Mandiant reported a spike in BadPaw infections linked to APT-C-36 exploiting CVE-2022-30190 (Follina) in Microsoft Office attachments. No major law enforcement actions have been publicly recorded to date, but multiple private sector reports (QiAnXin, Mandiant, Kaspersky) detail ongoing campaigns through early 2024.

🔍 Detection Indicators

Known file hashes include SHA256 9a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2 (loader) and 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2 (payload), as published by QiAnXin. Behavioral indicators include creation of scheduled tasks named "MicrosoftEdgeUpdateTask" and registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun pointing to %APPDATA%MicrosoftWindowsCachessvchost.exe. Network IOCs include C2 domains in the .top and .xyz TLDs using User-Agent strings mimicking "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.134 Safari/537.36".

☠️ Risk & Impact

BadPaw causes significant data exfiltration of sensitive government intelligence, financial records, and personally identifiable information (PII), leading to estimated losses exceeding $10 million collectively across Latin American targets. The malware's stealthy C2 infrastructure and multi-stage delivery have compromised over 200 organizations, with the most severe breaches in the Colombian tax authority (DIAN) and Ecuadorian banking sector.

🛡️ Mitigation

Defenders should implement application control policies to block unauthorized DLL side-loading, enable AMSI for PowerShell logging, and apply patches for CVE-2021-40444 and CVE-2022-30190. The MITRE ATT&CK technique T1574.002 (DLL Side-Loading) is central to this threat, and YARA rules specific to the BadPaw loader have been published by the QiAnXin Threat Intelligence Center (report URL: https://ti.qianxin.com).

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.