logo

Google exposes BadAudio malware used in APT24 espionage campaigns

ID: 4530ba19-524f-5259-8c65-f1428ee2a351

STIX ID: report--4530ba19-524f-5259-8c65-f1428ee2a351

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-11-20

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

APT24 (China‑linked) ran a three‑year targeted espionage campaign (Nov 2022–Sep 2025) delivering a heavily obfuscated loader named BadAudio via watering‑hole infections, supply‑chain compromise of a Taiwanese marketing firm (impacting ~1,000+ domains), and spearphishing lures. BadAudio uses control‑flow flattening, DLL search‑order hijacking, AES‑encrypted staging and C2, and has been observed loading Cobalt Strike; many samples remained poorly detected by antivirus, enabling persistent and stealthy intrusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.