Malware.View on attack.mitre.org
BLINDINGCAN is a remote access Trojan that has been used by the North Korean government since at least early 2020 in cyber operations against defense, engineering, and government organizations in Western Europe and the US.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
BLINDINGCAN has uploaded files from victim machines. |
| T1016 System Network Configuration Discovery |
BLINDINGCAN has collected the victim machine's local IP address information and MAC address. |
| T1027.002 Software Packing |
BLINDINGCAN has been packed with the UPX packer. |
| T1027.013 Encrypted/Encoded File |
BLINDINGCAN has obfuscated code using Base64 encoding. |
| T1036.005 Match Legitimate Resource Name or Location |
BLINDINGCAN has attempted to hide its payload by using legitimate file names such as "iconcache.db". |
| T1041 Exfiltration Over C2 Channel |
BLINDINGCAN has sent user and system information to a C2 server via HTTP POST requests. |
| T1059.003 Windows Command Shell |
BLINDINGCAN has executed commands via cmd.exe. |
| T1070.004 File Deletion |
BLINDINGCAN has deleted itself and associated artifacts from victim machines. |
| T1070.006 Timestomp |
BLINDINGCAN has modified file and directory timestamps. |
| T1071.001 Web Protocols |
BLINDINGCAN has used HTTPS over port 443 for command and control. |
| T1082 System Information Discovery |
BLINDINGCAN has collected from a victim machine the system name, processor information, and OS version. |
| T1083 File and Directory Discovery |
BLINDINGCAN can search, read, write, move, and execute files. |
| T1105 Ingress Tool Transfer |
BLINDINGCAN has downloaded files to a victim machine. |
| T1129 Shared Modules |
BLINDINGCAN has loaded and executed DLLs in memory during runtime on a victim machine. |
| T1132.001 Standard Encoding |
BLINDINGCAN has encoded its C2 traffic with Base64. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.