Malware

Novel BadAudio malware leveraged in years-long APT24 campaign

BleepingComputer reports that attacks spreading the newly discovered BadAudio malware have been launched by the China-nexus APT24 threat group as part of a three-year cyberespionage campaign aimed at Windows systems.

APT24 targeted over 20 public websites with illicit JavaScript code that displayed a bogus software update pop-up, tricking Windows users into downloading BadAudio between November 2022 and September 2025, according to a Google Threat Intelligence Group analysis.

Additional methods to distribute BadAudio have also been employed by APT24, which delivered the malware not only through more than 1,000 domains compromised through a supply chain attack against a Taiwanese digital marketing firm beginning July 2024, but also through spear-phishing intrusions that involved animal rescue organization spoofing beginning August 2024.

Execution of BadAudio, which disrupts programs' structured logic for obfuscation, facilitates system information gathering, encryption, and exfiltration before downloading and executing an AES-encrypted payload, said researchers, who highlighted the China-linked APT's proficiency in adaptive and persistent espionage.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Adware

You can skip this ad in 5 seconds