⚠
BADNEWS
rat2 mutex signatures
[BASIC_INFORMATION]
FAMILY_NAME:
BADNEWS
CATEGORY:
RAT
DESCRIPTION:
BADNEWS is a Remote Access Trojan (RAT) that has been used by the White Elephant APT group (also known as Patchwork or APT-C-35) in various espionage campaigns.
ALIASES:
BADNEWS RAT
TAGS:
remote_accessinfostealerc2apt
[MUTEX_SIGNATURES](2)
[MUTEX_01]
rendumm
ANALYST: @adhikara13 DATE: 2024-08-01
[MUTEX_02]
RfmbFv8D
ANALYST: @adhikara13 DATE: 2025-07-30
[QUICK_ACTIONS]
[THREAT_INTELLIGENCE]
ATTRIBUTION:
⚠White Elephant
⚠Patchwork
FIRST_OBSERVED:
2013
[SIGMA_RULE]
[STATISTICS]
MUTEX_COUNT:2
THREAT_ACTORS:2
ALIASES:1
TAGS:4
CATEGORY:RAT
Malware profile loaded successfully