Backdoor Batel - Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 19:17:45 UTC Home > List all groups > List all tools > List all groups using tool Backdoor Batel Tool: Backdoor Batel Names Backdoor Batel Batel Category Malware Type Backdoor Description Once the Odinaff Trojan has performed the initial compromise of the infected machine, a second piece of malware known as Batel is installed. This second malware infection is capable of running payloads solely in the memory, effectively enabling it to stealthily run in the background. Information Malpedia Last change to this tool card: 23 April 2020 Download this tool card in JSON format All groups using tool Backdoor Batel Changed Name Country Observed APT groups   Carbanak, Anunak 2013-Apr 2023 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=ed1ca12d-ad0f-4cdf-86b9-0d1df7b08774 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=ed1ca12d-ad0f-4cdf-86b9-0d1df7b08774 Page 1 of 1