Drooid Logo
Back to story perspectives

Full Breakdown

APT24's BADAUDIO Malware Campaign: A Deep-Dive into Cyber Espionage

11/22/2025, 4:46:49 AM

Overview of APT24's Cyber Espionage Campaign

APT24, a China-nexus threat actor also known as Pitty Tiger, has been conducting a sophisticated cyber espionage campaign since November 2022, utilizing a previously undocumented malware called BADAUDIO. This campaign has targeted organizations primarily in Taiwan, employing a range of tactics including supply chain attacks and targeted phishing campaigns. Google Threat Intelligence Group (GTIG) researchers have tracked this operation, which has evolved significantly over its nearly three-year duration.

Technical Analysis of BADAUDIO

BADAUDIO is a highly obfuscated first-stage downloader written in C++. It employs control flow flattening to resist reverse engineering and is designed to establish persistent access to compromised networks. The malware collects basic system information, encrypts it using a hard-coded AES key, and sends it to a command-and-control (C2) server. Upon receiving a response, it downloads and executes an AES-encrypted payload, which has included tools like Cobalt Strike Beacon.

The malware is typically delivered as a malicious Dynamic Link Library (DLL) that leverages DLL Search Order Hijacking for execution. APT24 has compromised over 20 legitimate websites to inject malicious JavaScript, which selectively targets Windows systems and prompts users to download BADAUDIO under the guise of a software update.

Supply Chain Attacks and Phishing Campaigns

A significant aspect of APT24's strategy has been the repeated compromise of a regional digital marketing firm in Taiwan. This breach allowed the group to inject malicious scripts into widely used JavaScript libraries, impacting over 1,000 domains. The attackers also utilized typosquatted domains to impersonate legitimate Content Delivery Networks (CDNs), further facilitating their supply chain attacks.

In addition to these tactics, APT24 has conducted targeted phishing campaigns since August 2024, using lures related to animal rescue organizations. These phishing emails often contained links to encrypted archives hosted on platforms like Google Drive and Microsoft OneDrive, allowing the group to bypass traditional security measures.

Criticism & Opposition

Experts have raised concerns about the implications of APT24's activities, particularly regarding the sophistication of their techniques and the potential for widespread impact on organizations in Taiwan and beyond. The use of advanced social engineering and supply chain compromises highlights the evolving nature of cyber threats linked to state-sponsored actors.

Official Statements & Responses

GTIG has emphasized the need for organizations to remain vigilant against such persistent threats. They have taken steps to protect users by adding compromised websites to the Safe Browsing blocklist and notifying affected organizations with technical details to help secure their systems.

Verbatim Quotes

  • “The use of advanced techniques like supply chain compromise, multi-layered social engineering, and the abuse of legitimate cloud services demonstrates the actor’s capacity for persistent and adaptive espionage,” GTIG notes.” — Google Threat Intelligence Group
  • “This nearly three-year campaign is a clear example of the continued evolution of APT24’s operational capabilities and highlights the sophistication of [China]-nexus threat actors.” — Google Threat Intelligence Group

Conflicting Reports & Gaps

While GTIG has provided extensive analysis of APT24's operations, there remains uncertainty regarding the full extent of the malware's deployment and the specific targets affected. Additionally, the effectiveness of antivirus solutions against BADAUDIO has been called into question, with many samples going undetected by multiple security products.

Conclusion

APT24's BADAUDIO campaign exemplifies the increasing sophistication of cyber espionage tactics employed by state-sponsored actors. As the threat landscape continues to evolve, organizations must enhance their defenses against such persistent and adaptive threats to safeguard their networks and sensitive information.