BadCandy campaign — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
October 31, 2025
Last Seen
October 31, 2025

BadCandy campaign is a threat campaign tracked across 2 threat clusters and 1 intelligence report mention on ThreatCluster. First observed October 31, 2025; most recent activity October 31, 2025.

Overview

BadCandy is a threat campaign that deploys implants on compromised devices to maintain persistence and control. A recent report indicates hundreds of Australian devices have been compromised by a BadCandy implant, underscoring ongoing activity and the campaign's scale in 2025.

Related Threat Clusters

Recent Intelligence Reports

  • Hundreds of Australian Devices Compromised with BadCandy Implant — Thecyberexpress · October 31, 2025

CVSS v3.1 Breakdown