MAR-10301706-1.v1 - North Korean Remote Access Tool: ECCENTRICBANDWAGON

2020-08-26 • USCISA •

https://www.cisa.gov/news-events/analysis-reports/ar20-239a

Thumbnail for MAR-10301706-1.v1 - North Korean Remote Access Tool: ECCENTRICBANDWAGON

DHS, the FBI, and the Department of Defense attributed ECCENTRICBANDWAGON to the North Korean government activity set tracked as HIDDEN COBRA. The Windows malware performs reconnaissance by logging keystrokes and capturing screenshots, with closely related variants using different storage paths and, in some cases, RC4-encrypted strings. One variant attempts cleanup by deleting a control file and terminating Windows Explorer, potentially alerting the victim. CISA published hashes and a YARA rule to support detection and incident response.

Indicators of Compromise

Type Value First Seen Last Seen
YARA CISA_3P_10301706_01 2020-08-26 2020-08-26
HASH 32a4de070ca005d35a88503717157b0… 2020-08-26 2020-08-26
HASH 9ea5aa00e0a738b74066c61b1d35331… 2020-08-05 2020-08-26
HASH efd470cfa90b918e5d558e5c8c38213… 2019-01-22 2020-08-26
HASH c6930e298bba86c01d0fe2c8262c46b… 2019-01-13 2020-08-26

Related Actors

Related Reports

« Back