Malware.View on attack.mitre.org
ECCENTRICBANDWAGON is a remote access Trojan (RAT) used by North Korean cyber actors that was first identified in August 2020. It is a reconnaissance tool--with keylogging and screen capture functionality--used for information gathering on compromised systems.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
ECCENTRICBANDWAGON has encrypted strings with RC4. |
| T1056.001 Keylogging |
ECCENTRICBANDWAGON can capture and store keystrokes. |
| T1059.003 Windows Command Shell |
ECCENTRICBANDWAGON can use cmd to execute commands on a victim’s machine. |
| T1070.004 File Deletion |
ECCENTRICBANDWAGON can delete log files generated from the malware stored at |
| T1074.001 Local Data Staging |
ECCENTRICBANDWAGON has stored keystrokes and screenshots within the |
| T1113 Screen Capture |
ECCENTRICBANDWAGON can capture screenshots and store them locally. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.