Malware
BADCALL
- First Reported
- Dec 17, 2025
- Latest Reported
- Dec 17, 2025
Reported Context (1)
- 23.27.140[.]49 open directory data on port 8080Upon analysis, the ELF exhibits similar behavior to the BADCALL backdoor that was previously seen in the 3CX supply chain attack by Lazarus. One of these, Hunt.io and Acronis Trace Lazarus and Kimsuky Infrastructure Across Campaigns
Malware (5)
People (1)
Threat Actors (4)
MITRE ATT&CK (3)
Vendors (2)
Products (1)
Tools (29)
Countries (4)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.