BadRabbit, a new version of NotPetya, also has an infector allowing for lateral movements. The malware uses one of the leaked NSA exploits: EternalRomance (one of two exploits that were also used in the previous attack of Petya/NotPetyA). The malware must run with Administration privileges, but no UAC bypass technique has been deployed. It relies purely on social engineering, trying to convince the user to elevate it. After being run, it drops and deploys the main module in C:Windows. This time, it is named infpub.dat.”]

