ATT&CKSoftwareBLINDINGCAN

BLINDINGCAN

S0520

Malware.View on attack.mitre.org

About this malware

BLINDINGCAN is a remote access Trojan that has been used by the North Korean government since at least early 2020 in cyber operations against defense, engineering, and government organizations in Western Europe and the US.

Techniques used22

Procedure examples22

TechniqueProcedure example
T1005
Data from Local System

BLINDINGCAN has uploaded files from victim machines.

T1016
System Network Configuration Discovery

BLINDINGCAN has collected the victim machine's local IP address information and MAC address.

T1027.002
Software Packing

BLINDINGCAN has been packed with the UPX packer.

T1027.013
Encrypted/Encoded File

BLINDINGCAN has obfuscated code using Base64 encoding.

T1036.005
Match Legitimate Resource Name or Location

BLINDINGCAN has attempted to hide its payload by using legitimate file names such as "iconcache.db".

T1041
Exfiltration Over C2 Channel

BLINDINGCAN has sent user and system information to a C2 server via HTTP POST requests.

T1059.003
Windows Command Shell

BLINDINGCAN has executed commands via cmd.exe.

T1070.004
File Deletion

BLINDINGCAN has deleted itself and associated artifacts from victim machines.

T1070.006
Timestomp

BLINDINGCAN has modified file and directory timestamps.

T1071.001
Web Protocols

BLINDINGCAN has used HTTPS over port 443 for command and control.

T1082
System Information Discovery

BLINDINGCAN has collected from a victim machine the system name, processor information, and OS version.

T1083
File and Directory Discovery

BLINDINGCAN can search, read, write, move, and execute files.

T1105
Ingress Tool Transfer

BLINDINGCAN has downloaded files to a victim machine.

T1129
Shared Modules

BLINDINGCAN has loaded and executed DLLs in memory during runtime on a victim machine.

T1132.001
Standard Encoding

BLINDINGCAN has encoded its C2 traffic with Base64.

View all 22 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. NHS UK BLINDINGCAN Aug 2020 Open source
    NHS Digital . (2020, August 20). BLINDINGCAN Remote Access Trojan. Retrieved August 20, 2020.
  2. US-CERT BLINDINGCAN Aug 2020 Open source
    US-CERT. (2020, August 19). MAR-10295134-1.v1 – North Korean Remote Access Trojan: BLINDINGCAN. Retrieved August 19, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.