Skip to main content
Mallory
MalwareUsed by 1 actor

BADAUDIO

BADAUDIO is a highly obfuscated C++ first-stage downloader used by the China-nexus threat actor APT24 in a multi-year cyberespionage campaign active from at least November 2022 through September 2025. It primarily targeted Windows systems, with reporting indicating a focus on organizations in Taiwan and the United States and sectors including healthcare, construction, mining, non-profits, and telecommunications. Delivery methods directly mentioned include watering hole attacks on more than 20 legitimate public websites, a supply-chain compromise of a Taiwanese digital marketing firm that affected over 1,000 domains, and spear-phishing campaigns including lures spoofing an animal rescue organization. Separate campaigns also abused Google Drive and OneDrive to distribute encrypted archives containing BADAUDIO, and phishing emails included tracking pixels to confirm opens.

Technically, BADAUDIO is described as a first-stage downloader implemented as a DLL and using DLL search order hijacking. It employs heavy obfuscation, including control flow flattening and structured-logic disruption, to resist reverse engineering and evade detection. The malware gathers host/system information, with one report noting that system information was embedded in cookie headers when communicating with command-and-control infrastructure. It can download, decrypt, and execute AES-encrypted payloads from a hard-coded C2 server, including second-stage payloads such as Cobalt Strike Beacon. Reporting also states that payloads may be decrypted and executed in memory.

Associated campaign tradecraft includes browser fingerprinting using FingerprintJS, fake Chrome/software update pop-ups, typosquatted CDN infrastructure for malicious JavaScript delivery, and selective targeting of Windows users while excluding macOS, iOS, and Android visitors. Additional activity mentioned in connection with the broader campaign includes persistent remote access, encrypted payload delivery, and use of SSH backdoors, certificate spoofing, and proxy routing via hijacked routers. High-confidence indicators mentioned at a general level include malicious DLLs, encrypted archives, suspicious file access, network requests to typosquatted CDN domains, and related GTI IOC collections made available by Google.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
BlackTech

A China-nexus threat actor has been conducting a sophisticated, multi-year espionage campaign using a custom malware downloader, compromising regional infrastructure…

via secpod blogsecpod.com
MITRE ATT&CK

Techniques & procedures

10 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

4 techniques
T1189Drive-by CompromiseEvidence1

"APT24 targeted over 20 public websites with illicit JavaScript code that displayed a bogus software update pop-up, tricking Windows users into downloading BadAudio"

T1195Supply Chain CompromiseEvidence2

"more than 1,000 domains compromised through a supply chain attack against a Taiwanese digital marketing firm beginning July 2024"

T1566.001Spearphishing AttachmentEvidence1

"APT24 concurrently conducted highly targeted social engineering campaigns. Lures, such as an email purporting to be from an animal rescue organization, leveraged social engineering to elicit user interaction and drive direct malware downloads from attacker-controlled domains."

T1566.003Spearphishing via ServiceEvidence2

"spear-phishing intrusions that involved animal rescue organization spoofing beginning August 2024"

Execution

1 technique
T1204User ExecutionEvidence1
TacticExecution

"...leveraged social engineering to elicit user interaction and drive direct malware downloads..."

Stealth

1 technique
T1027Obfuscated Files or InformationEvidence2
TacticStealth

"Execution of BadAudio, which disrupts programs' structured logic for obfuscation"

Discovery

1 technique
T1082System Information DiscoveryEvidence1
TacticDiscovery

"facilitates system information gathering"

T1105Ingress Tool TransferEvidence2

"before downloading and executing an AES-encrypted payload"

T1573Encrypted ChannelEvidence1

"before downloading and executing an AES-encrypted payload"

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

"encryption, and exfiltration"

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping10

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.