The BADNEWS Trojan was first spotted two years ago, but its activity has not halted yet. It is believed to be the creation of a hacking group called Patchwork, which tends to target users located in India mainly. This group also is known as Monsoon and Dropping Elephant. Over the years, the Patchwork APT (Advanced Persistent Threat) has introduced several updates to the BADNEWS Trojan. They have made sure that this threat is able to detect whether it is being run in a malware debugging environment and, if it is, cease operating. The BADNEWS Trojan’s ability to remain undetected by anti-malware tools also has been improved.
Propagates via Spear-Phishing Emails
The BADNEWS Trojan is propagated via email spear-phishing campaigns mainly. The emails would contain an attachment that is meant to attract the attention of the user and convince them to launch the attached file. Often, the attachment would appear to carry important information regarding the Pakistani Commission for Atomic Energy or The Pakistani Ministry of Interior Affairs. The attachment is meant to exploit CVE-2015-2545 and CVE-2017-0261, which are known Microsoft Office vulnerabilities.
The BADNEWS Trojan can serve as a backdoor for the attackers to plant additional malware on the infiltrated host. This hacking tool also can serve to collect information about the victim’s system and then transfer it to its operators. The BADNEWS Trojan can be used for scanning the hard disk partitions in search for .doc, .ppt, .pptx, .docx, .xls, .xlsx. and .pdf files. It is clear that the attackers are after documents that may carry important data potentially. The BADNEWS Trojan has a keylogger module, which can be used to collect more information. The attackers also can use this hacking tool to take screenshots of the user’s desktop and opened tabs.
Despite the Patchwork hacking group not being considered one of the highest-tier APTs out there, their attacks are still not to be underestimated. They build their own arsenal of hacking tools and are capable of carrying out very destructive campaigns.
Do You Suspect Your PC May Be Infected with BADNEWS & Other Threats? Scan Your PC with SpyHunterSpyHunter is a powerful malware remediation and protection tool designed to help provide PC users with in-depth system security analysis, detection and removal of a wide range of threats like BADNEWS as well as a one-on-one tech support service. Download SpyHunter's FREE Malware Remover
Security Doesn't Let You Download SpyHunter or Access the Internet?Solutions: Your computer may have malware hiding in memory that prevents any program, including SpyHunter, from executing on your computer. Follow to download SpyHunter and gain access to the Internet:
- Use an alternative browser. Malware may disable your browser. If you're using IE, for example, and having problems downloading SpyHunter, you should open Firefox, Chrome or Safari browser instead.
- Use a removable media. Download SpyHunter on another clean computer, burn it to a USB flash drive, DVD/CD, or any preferred removable media, then install it on your infected computer and run SpyHunter's malware scanner.
- Start Windows in Safe Mode. If you can not access your Window's desktop, reboot your computer in "Safe Mode with Networking" and install SpyHunter in Safe Mode.
- IE Users: Disable proxy server for Internet Explorer to browse the web with Internet Explorer or update your anti-spyware program. Malware modifies your Windows settings to use a proxy server to prevent you from browsing the web with IE.