MAR-10271944-3.v1 – North Korean Trojan: BUFFETLINE
2020-02-14 • USCISA •
CISA, FBI, and DoD analyzed BUFFETLINE, a Trojan malware variant attributed to North Korean government activity tracked as HIDDEN COBRA. The report describes a full-featured beaconing implant that uses PolarSSL for session authentication and a FakeTLS scheme with modified RC4-style encoding for network traffic. The malware can download, upload, delete, and execute files, enable Windows command-line access, create and terminate processes, and enumerate target systems. The advisory provides malware behavior and defensive context to help organizations prioritize detection and mitigation of North Korean government-linked tooling.
Related Actors
Related Reports
2020-02-25 •
80% Match
#HiddenCobra
#ARTFULPIE
#HOTCROISSANT
#CROWDEDFLOUNDER
#SLICKSHOES
#BISTROMATH
#BUFFETLINE
#T1082
#T1090
#T1005
#T1041
#T1083
#T1027
#T1124
#T1204
#T1057
#T1003
#T1105
#T1055
#T1016
#T1048
#T1074
#T1056
#T1033
#T1012
#T1132
#T1043
#T1060
#T1064
#T1193
#T1065
#T1050
#T1024
Shares tags: HiddenCobra, BUFFETLINE • Published within a month
Shares tag: HiddenCobra • Same author: USCISA • Published within a week
Shares tag: HiddenCobra • Same author: USCISA • Published within a week
Shares tag: HiddenCobra • Same author: USCISA • Published within a week
Shares tag: HiddenCobra • Same author: USCISA • Published within a week
Shares tag: HiddenCobra • Same author: USCISA • Published within a week