Software: Bad Rabbit, Diskcoder.D

ID S0005
Type Malware

Bad Rabbit is a self-propagating (“wormable”) ransomware that affected the transportation sector in Ukraine.1

Techniques Used

  • Drive-by Compromise - Bad Rabbit ransomware spreads through drive-by attacks where insecure websites are compromised. While the target is visiting a legitimate website, a malware dropper is being downloaded from the threat actor’s infrastructure.2
  • User Execution - Bad Rabbit is disguised as an Adobe Flash installer. When the file is opened it starts locking the infected computer.2