#BISTROMATH

Malware/Tool

2020-02-14 • MAR-10265965-1.v1 – North Korean Trojan: BISTROMATH

BISTROMATH is a full-featured Windows remote-access Trojan attributed by U.S. government analysts to North Korean HIDDEN COBRA activity. Its implants use simple XOR encoding for network traffic and support system surveys, file upload and download, process and command execution, microphone monitoring, clipboard collection, and screen surveillance. Companion CAgent11 graphical controllers let operators interact with infected hosts and build customized implants. Trojanized executables conceal configuration data and shellcode in a fake bitmap, decode it in memory, and can check for virtual machines, sandboxes, and debugging artifacts before loading the implant.

Tagged Reports

« Back