MAR-10301706-1.v1 - North Korean Remote Access Tool: ECCENTRICBANDWAGON
2020-08-26 • USCISA •
DHS, the FBI, and the Department of Defense attributed ECCENTRICBANDWAGON to the North Korean government activity set tracked as HIDDEN COBRA. The Windows malware performs reconnaissance by logging keystrokes and capturing screenshots, with closely related variants using different storage paths and, in some cases, RC4-encrypted strings. One variant attempts cleanup by deleting a control file and terminating Windows Explorer, potentially alerting the victim. CISA published hashes and a YARA rule to support detection and incident response.
Indicators of Compromise
Related Actors
Related Reports
Shares tags: YARA, HiddenCobra • Same author: USCISA • Published within a week
Shares tags: YARA, HiddenCobra • Same author: USCISA • Published within a week
Shares tags: YARA, HiddenCobra • Same author: USCISA
Shares tags: YARA, HiddenCobra • Same author: USCISA
Shares tags: YARA, HiddenCobra • Same author: USCISA
Shares tags: YARA, HiddenCobra • Same author: USCISA