logo

Hackers Exploit Legitimate Websites to Deliver BadSpace Windows Backdoor

ID: d92bb2a8-7661-52b7-a463-19c62f009013

STIX ID: report--d92bb2a8-7661-52b7-a463-19c62f009013

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-06-17

Date Updated: 2026-05-06

Author: [email protected] (The Hacker News)

...
...

Legitimate-but-compromised websites (including WordPress sites) are being used to deliver a Windows backdoor named BadSpace by overlaying pages with fake Google Chrome update pop-ups which drop either the backdoor or a JScript downloader; the multi-stage chain collects device and visitor data, contacts hard-coded C2 domains, and then deploys BadSpace which implements anti-sandbox checks, scheduled-task persistence, information harvesting, remote command execution (screenshots, cmd.exe execution, file read/write), and can remove its scheduled task. Analysis links the campaign to the JavaScript-based SocGholish/FakeUpdates ecosystem, and multiple security vendors have reported similar fake-update lures in active distribution campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.