Bad Rabbit Ransomware
Overview
A comprehensive overview based on
MITRE ATT&CK®
[Link]
S0606/
Overview
• Bad Rabbit is a self-propagating ransomware
from 2017, affecting primarily the Ukrainian
transportation sector and also targeting
organizations in Russia. It is known by its
software ID S0606 and operates on Windows
platforms.
Techniques Used
• - Abuse Elevation Control Mechanism
• - Brute Force: Password Spraying
• - Data Encrypted for Impact
• - Drive-by Compromise
• - Exploitation of Remote Services
• - Firmware Corruption
• - Masquerading as Flash Player installer
• - Uses various Windows API calls
• - Network Share Discovery
Groups That Use This Software
• Sandworm Team is associated with the usage
of Bad Rabbit ransomware.
References
• - [Link], Bad Rabbit ransomware
analysis
• - [Link], Bad Rabbit: Improved
ransomware
• - [Link], Implications of IT Ransomware
for ICS Environments