LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0606: Bad Rabbit

Bad Rabbit is a self-propagating ransomware that affected the Ukrainian transportation sector in 2017. Bad Rabbit has also targeted organizations and consumers in Russia. [1][2][3]

EnterpriseS0606MalwareObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Bad Rabbit matters because ATT&CK describes it as self-propagating Windows ransomware associated with real operational disruption, including the Ukrainian transportation sector in 2017 and targets in Russia. For leaders, the key decision value is not the malware name itself; it is whether Windows estates, shared services, identity controls, backups, and IT/ICS segmentation can withstand ransomware that combines user-driven initial access, credential access, lateral movement, and encryption for impact.

Executive priority

Prioritize Bad Rabbit as a resilience and readiness test case for ransomware affecting business continuity and potentially cyber-physical operations. Executives should ask whether the organization can prove: Windows endpoint visibility, protected credential stores, monitored remote service use, controlled SMB/network shares, recoverable backups, and clear incident procedures for rapid isolation. Because ATT&CK links this malware to ICS impact techniques such as Loss of Productivity and Revenue, organizations with operational technology should validate IT-to-OT separation and downtime response evidence, not just endpoint malware prevention.

Technical view

ATT&CK lists Bad Rabbit on Windows and relates it to techniques spanning drive-by compromise, malicious file execution, LSASS memory access, password spraying, scheduled tasks, process and network share discovery, lateral tool transfer, exploitation of remote services, service execution, rundll32 proxy execution, UAC bypass, data encryption for impact, firmware corruption, and ICS loss of productivity/revenue. SOC and IR teams should validate visibility across the full chain: browser/download activity, suspicious Windows process execution, credential access attempts against LSASS, abnormal authentication patterns, SMB/share enumeration and file transfer, service or scheduled task creation, and rapid file encryption or availability-impacting changes.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry
  • Windows service creation and service control manager activity
  • Scheduled task creation, modification, and execution events
  • Rundll32 execution context and child process relationships
  • LSASS access events and endpoint security alerts related to credential dumping behavior

Detection direction

  • Map detection coverage to the ATT&CK relationships rather than relying on a single Bad Rabbit signature, since official ATT&CK detection text is not provided.
  • Correlate user execution or drive-by delivery signals with follow-on Windows behaviors such as scheduled tasks, service execution, rundll32 activity, discovery, credential access, and lateral movement.
  • Tune for ransomware behavior on shared storage: rapid file modification, encryption-like write patterns, and activity from unusual hosts or accounts.
  • Validate alerting for LSASS access and abnormal authentication attempts, while accounting for legitimate administration and security tooling to reduce false positives.
  • Review SMB and network share discovery baselines; administrative scanning and backup operations can look noisy, so detections should consider source host, account role, timing, and follow-on execution.

Mitigation priorities

  • Strengthen ransomware recovery first: maintain tested, protected backups and rehearsed restoration procedures for critical Windows systems and shared data.
  • Reduce lateral movement opportunity by limiting SMB exposure, enforcing least privilege, and segmenting critical business and OT networks from general user workstations.
  • Harden identity controls against credential access and password spraying through strong authentication policy, privileged account controls, and monitoring of broad login attempts.
  • Restrict or monitor administrative execution paths commonly abused in the related techniques, including scheduled tasks, service creation, rundll32, and remote service execution.
  • Patch and vulnerability-manage remotely reachable services to reduce exploitation paths used for lateral movement.
Additional notes and limits

This take is based on ATT&CK S0606 Bad Rabbit, its official description, external references from Secure List, ESET, Dragos, and the supplied relationships to Sandworm Team and related ATT&CK techniques. The most defensible use for defenders is as a ransomware behavior coverage checklist across Windows endpoint, identity, lateral movement, shared storage, and IT/ICS resilience.

MITRE does not provide official detection text for this object, and the object itself lists tactics as not specified. Several related technique descriptions are general ATT&CK technique descriptions rather than Bad Rabbit-specific procedure detail. Local validation, telemetry availability, asset criticality, and environment-specific baselines are required before claiming coverage or exposure.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Bad Rabbit

Bad Rabbit is a self-propagating ransomware that affected the Ukrainian transportation sector in 2017. Bad Rabbit has also targeted organizations and consumers in Russia. [1][2][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

15 rows
DomainIDNameRelationship / procedure
EnterpriseT1486Data Encrypted for Impact

Bad Rabbit has encrypted files and disks using AES-128-CBC and RSA-2048.[1]

EnterpriseT1110.003Password SprayingSub-technique

Bad Rabbit’s infpub.dat file uses NTLM login credentials to brute force Windows machines.[1]

EnterpriseT1495Firmware Corruption

Bad Rabbit has used an executable that installs a modified bootloader to prevent normal boot-up.[1]

EnterpriseT1569.002Service ExecutionSub-technique

Bad Rabbit drops a file named infpub.datinto the Windows directory and is executed through SCManager and rundll.exe.

EnterpriseT1053.005Scheduled TaskSub-technique

Bad Rabbit’s infpub.dat file creates a scheduled task to launch a malicious executable.[1]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

Bad Rabbit has masqueraded as a Flash Player installer through the executable file install_flash_player.exe.[2][1]

EnterpriseT1189Drive-by Compromise

Bad Rabbit spread through watering holes on popular sites by injecting JavaScript into the HTML body or a .js file.[2][1]

EnterpriseT1003.001LSASS MemorySub-technique

Bad Rabbit has used Mimikatz to harvest credentials from the victim's machine.[2]

EnterpriseT1548.002Bypass User Account ControlSub-technique

Bad Rabbit has attempted to bypass UAC and gain elevated administrative privileges.[1]

EnterpriseT1057Process Discovery

Bad Rabbit can enumerate all running processes to compare hashes.[1]

EnterpriseT1135Network Share Discovery

Bad Rabbit enumerates open SMB shares on internal victim networks.[2]

EnterpriseT1210Exploitation of Remote Services

Bad Rabbit used the EternalRomance SMB exploit to spread through victim networks.[1]

EnterpriseT1218.011Rundll32Sub-technique

Bad Rabbit has used rundll32 to launch a malicious DLL as C:Windowsinfpub.dat.[1]

EnterpriseT1204.002Malicious FileSub-technique

Bad Rabbit has been executed through user installation of an executable disguised as a flash installer.[2][1]

EnterpriseT1106Native API

Bad Rabbit has used various Windows API calls.[2]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0034: Sandworm Team

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.[1][2] This group has been active since at least 2009.[3][4][5][6]

In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.[1][2] Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.[7]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
7a9204e572f8f4e7...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundle7a9204e572f8…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  2. [2]
    ESET Bad Rabbit

    M.Léveille, M-E.. (2017, October 24). Bad Rabbit: Not‑Petya is back with improved ransomware. Retrieved January 28, 2021.

    Open source URL
  3. [3]
    Dragos Apr 2019

    Joe Slowik. (2019, April 10). Implications of IT Ransomware for ICS Environments. Retrieved October 27, 2019.

    Open source URL
  4. [4]
    Secureworks IRON VIKING

    Secureworks. (2020, May 1). IRON VIKING Threat Profile. Retrieved June 10, 2020.

    Open source URL
  5. [5]
    Dragos Apr 2019

    Joe Slowik. (2019, April 10). Implications of IT Ransomware for ICS Environments. Retrieved October 27, 2019.

    Open source URL
  6. [6]
    Dragos Apr 2019

    Joe Slowik. (2019, April 10). Implications of IT Ransomware for ICS Environments. Retrieved October 27, 2019.

    Open source URL
  7. [7]
    ESET Bad Rabbit

    M.Léveille, M-E.. (2017, October 24). Bad Rabbit: Not‑Petya is back with improved ransomware. Retrieved January 28, 2021.

    Open source URL
  8. [8]
    ESET Bad Rabbit

    M.Léveille, M-E.. (2017, October 24). Bad Rabbit: Not‑Petya is back with improved ransomware. Retrieved January 28, 2021.

    Open source URL
  9. [9]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  10. [10]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  11. [11]
    mitre-attackS0606
    Open source URL
  12. [12]
    mitre-attackS0606
    Open source URL
  13. [13]
    mitre-attackS0606
    Open source URL
  14. [14]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  15. [15]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  16. [16]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  17. [17]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  18. [18]
    Secureworks IRON VIKING

    Secureworks. (2020, May 1). IRON VIKING Threat Profile. Retrieved June 10, 2020.

    Open source URL
  19. [19]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  20. [20]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  21. [21]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  22. [22]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  23. [23]
    ESET Bad Rabbit

    M.Léveille, M-E.. (2017, October 24). Bad Rabbit: Not‑Petya is back with improved ransomware. Retrieved January 28, 2021.

    Open source URL
  24. [24]
    ESET Bad Rabbit

    M.Léveille, M-E.. (2017, October 24). Bad Rabbit: Not‑Petya is back with improved ransomware. Retrieved January 28, 2021.

    Open source URL
  25. [25]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  26. [26]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  27. [27]
    ESET Bad Rabbit

    M.Léveille, M-E.. (2017, October 24). Bad Rabbit: Not‑Petya is back with improved ransomware. Retrieved January 28, 2021.

    Open source URL
  28. [28]
    ESET Bad Rabbit

    M.Léveille, M-E.. (2017, October 24). Bad Rabbit: Not‑Petya is back with improved ransomware. Retrieved January 28, 2021.

    Open source URL
  29. [29]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  30. [30]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  31. [31]
    ESET Bad Rabbit

    M.Léveille, M-E.. (2017, October 24). Bad Rabbit: Not‑Petya is back with improved ransomware. Retrieved January 28, 2021.

    Open source URL
  32. [32]
    ESET Bad Rabbit

    M.Léveille, M-E.. (2017, October 24). Bad Rabbit: Not‑Petya is back with improved ransomware. Retrieved January 28, 2021.

    Open source URL
  33. [33]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  34. [34]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  35. [35]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  36. [36]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  37. [37]
    ESET Bad Rabbit

    M.Léveille, M-E.. (2017, October 24). Bad Rabbit: Not‑Petya is back with improved ransomware. Retrieved January 28, 2021.

    Open source URL
  38. [38]
    ESET Bad Rabbit

    M.Léveille, M-E.. (2017, October 24). Bad Rabbit: Not‑Petya is back with improved ransomware. Retrieved January 28, 2021.

    Open source URL
  39. [39]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  40. [40]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  41. [41]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  42. [42]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  43. [43]
    ESET Bad Rabbit

    M.Léveille, M-E.. (2017, October 24). Bad Rabbit: Not‑Petya is back with improved ransomware. Retrieved January 28, 2021.

    Open source URL
  44. [44]
    ESET Bad Rabbit

    M.Léveille, M-E.. (2017, October 24). Bad Rabbit: Not‑Petya is back with improved ransomware. Retrieved January 28, 2021.

    Open source URL
  45. [45]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  46. [46]
    Secure List Bad Rabbit

    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

    Open source URL
  47. [47]
    ESET Bad Rabbit

    M.Léveille, M-E.. (2017, October 24). Bad Rabbit: Not‑Petya is back with improved ransomware. Retrieved January 28, 2021.

    Open source URL
  48. [48]
    ESET Bad Rabbit

    M.Léveille, M-E.. (2017, October 24). Bad Rabbit: Not‑Petya is back with improved ransomware. Retrieved January 28, 2021.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.