ATT&CKReferencesCISA EB Aug 2020

CISA EB Aug 2020

Cybersecurity and Infrastructure Security Agency. (2020, August 26). MAR-10301706-1.v1 - North Korean Remote Access Tool: ECCENTRICBANDWAGON. Retrieved March 18, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareECCENTRICBANDWAGON

ECCENTRICBANDWAGON has encrypted strings with RC4.

T1056.001
Keylogging
MalwareECCENTRICBANDWAGON

ECCENTRICBANDWAGON can capture and store keystrokes.

T1059.003
Windows Command Shell
MalwareECCENTRICBANDWAGON

ECCENTRICBANDWAGON can use cmd to execute commands on a victim’s machine.

T1070.004
File Deletion
MalwareECCENTRICBANDWAGON

ECCENTRICBANDWAGON can delete log files generated from the malware stored at C:\windows\temp\tmp0207.

T1074.001
Local Data Staging
MalwareECCENTRICBANDWAGON

ECCENTRICBANDWAGON has stored keystrokes and screenshots within the %temp%\GoogleChrome, %temp%\Downloads, and %temp%\TrendMicroUpdate directories.

T1113
Screen Capture
MalwareECCENTRICBANDWAGON

ECCENTRICBANDWAGON can capture screenshots and store them locally.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.