SYMBOLCOMMON_NAMEaka. SYNONYMS
win.badaudio (Back to overview)

BADAUDIO

Actor(s): APT24

VTCollection    

According to Google, BADAUDIO is a custom first-stage downloader written in C++ that downloads, decrypts, and executes an AES-encrypted payload from a hard-coded command and control (C2) server. The malware collects basic system information, encrypts it using a hard-coded AES key, and sends it as a cookie value with the GET request to fetch the payload. The payload, in one case identified as Cobalt Strike Beacon, is decrypted with the same key and executed in memory.

References
2026-02-22 ⋅ Securite360.net ⋅ Muffin
OPSEC on a Budget: What BadAudio Reveals About APT24
BADAUDIO
2025-11-20 ⋅ Google ⋅ Dan Perez, Harsh Parashar, Tierra Duncan
Beyond the Watering Hole: APT24's Pivot to Multi-Vector Attacks
BADAUDIO Cobalt Strike
Yara Rules
[TLP:WHITE] win_badaudio_auto (20260917 | Detects win.badaudio.)
rule win_badaudio_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.badaudio."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.badaudio"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 51 50 e8???????? 83c40c 31db 85c0 0f94c3 }
            // n = 7, score = 300
            //   51                   | push                ecx
            //   50                   | push                eax
            //   e8????????           |                     
            //   83c40c               | add                 esp, 0xc
            //   31db                 | xor                 ebx, ebx
            //   85c0                 | test                eax, eax
            //   0f94c3               | sete                bl

        $sequence_1 = { 80f136 884c2440 345c 880424 }
            // n = 4, score = 300
            //   80f136               | xor                 cl, 0x36
            //   884c2440             | mov                 byte ptr [esp + 0x40], cl
            //   345c                 | xor                 al, 0x5c
            //   880424               | mov                 byte ptr [esp], al

        $sequence_2 = { e8???????? 8b7d08 c6470c00 807de000 0f8447ffffff 8b45dc }
            // n = 6, score = 300
            //   e8????????           |                     
            //   8b7d08               | mov                 edi, dword ptr [ebp + 8]
            //   c6470c00             | mov                 byte ptr [edi + 0xc], 0
            //   807de000             | cmp                 byte ptr [ebp - 0x20], 0
            //   0f8447ffffff         | je                  0xffffff4d
            //   8b45dc               | mov                 eax, dword ptr [ebp - 0x24]

        $sequence_3 = { 8d7110 83c0f0 8b1a 8b5204 8945cc 8975c8 894db8 }
            // n = 7, score = 300
            //   8d7110               | lea                 esi, [ecx + 0x10]
            //   83c0f0               | add                 eax, -0x10
            //   8b1a                 | mov                 ebx, dword ptr [edx]
            //   8b5204               | mov                 edx, dword ptr [edx + 4]
            //   8945cc               | mov                 dword ptr [ebp - 0x34], eax
            //   8975c8               | mov                 dword ptr [ebp - 0x38], esi
            //   894db8               | mov                 dword ptr [ebp - 0x48], ecx

        $sequence_4 = { 89c1 c1c11e 89c6 c1c613 31ce c1c00a 31f0 }
            // n = 7, score = 300
            //   89c1                 | mov                 ecx, eax
            //   c1c11e               | rol                 ecx, 0x1e
            //   89c6                 | mov                 esi, eax
            //   c1c613               | rol                 esi, 0x13
            //   31ce                 | xor                 esi, ecx
            //   c1c00a               | rol                 eax, 0xa
            //   31f0                 | xor                 eax, esi

        $sequence_5 = { 7226 83f83f 7714 90 8d4801 894e28 c644062c00 }
            // n = 7, score = 300
            //   7226                 | jb                  0x28
            //   83f83f               | cmp                 eax, 0x3f
            //   7714                 | ja                  0x16
            //   90                   | nop                 
            //   8d4801               | lea                 ecx, [eax + 1]
            //   894e28               | mov                 dword ptr [esi + 0x28], ecx
            //   c644062c00           | mov                 byte ptr [esi + eax + 0x2c], 0

        $sequence_6 = { 51 50 e8???????? 83c40c 8b4614 2b4610 034604 }
            // n = 7, score = 300
            //   51                   | push                ecx
            //   50                   | push                eax
            //   e8????????           |                     
            //   83c40c               | add                 esp, 0xc
            //   8b4614               | mov                 eax, dword ptr [esi + 0x14]
            //   2b4610               | sub                 eax, dword ptr [esi + 0x10]
            //   034604               | add                 eax, dword ptr [esi + 4]

        $sequence_7 = { 3a540803 7540 83c104 83f920 75ce }
            // n = 5, score = 300
            //   3a540803             | cmp                 dl, byte ptr [eax + ecx + 3]
            //   7540                 | jne                 0x42
            //   83c104               | add                 ecx, 4
            //   83f920               | cmp                 ecx, 0x20
            //   75ce                 | jne                 0xffffffd0

        $sequence_8 = { 328fe7000000 884e07 8a442402 3287e8000000 884608 8a442405 3287e9000000 }
            // n = 7, score = 300
            //   328fe7000000         | xor                 cl, byte ptr [edi + 0xe7]
            //   884e07               | mov                 byte ptr [esi + 7], cl
            //   8a442402             | mov                 al, byte ptr [esp + 2]
            //   3287e8000000         | xor                 al, byte ptr [edi + 0xe8]
            //   884608               | mov                 byte ptr [esi + 8], al
            //   8a442405             | mov                 al, byte ptr [esp + 5]
            //   3287e9000000         | xor                 al, byte ptr [edi + 0xe9]

        $sequence_9 = { e8???????? 83c404 50 89e2 8b0e c70600000000 }
            // n = 6, score = 300
            //   e8????????           |                     
            //   83c404               | add                 esp, 4
            //   50                   | push                eax
            //   89e2                 | mov                 edx, esp
            //   8b0e                 | mov                 ecx, dword ptr [esi]
            //   c70600000000         | mov                 dword ptr [esi], 0

    condition:
        7 of them and filesize < 1420288
}
Download all Yara Rules