BADNEWS

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[BADNEWS](https://attack.mitre.org/software/S0128) is malware that has been used by the actors responsible for the [Patchwork](https://attack.mitre.org/groups/G0040) campaign. Its name was given due to its use of RSS feeds, forums, and blogs for command and control. (Citation: Forcepoint Monsoon) (Citation: TrendMicro Patchwork Dec 2017)

Associated Techniques (24)
ID ATT&CK Tactics
T1005 Data from Local System -
T1025 Data from Removable Media -
T1036.001 Invalid Code Signature -
T1036.005 Match Legitimate Resource Name or Location -
T1039 Data from Network Shared Drive -
T1053.005 Scheduled Task -
T1055.012 Process Hollowing -
T1056.001 Keylogging -
T1059.003 Windows Command Shell -
T1071.001 Web Protocols -
T1074.001 Local Data Staging -
T1083 File and Directory Discovery -
T1102.001 Dead Drop Resolver -
T1102.002 Bidirectional Communication -
T1105 Ingress Tool Transfer -
Used by Actors (1)
Metadata
ID: 640
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00