SYSCON

S0464

Malware.View on attack.mitre.org

About this malware

SYSCON is a backdoor that has been in use since at least 2017 and has been associated with campaigns involving North Korean themes. SYSCON has been delivered by the CARROTBALL and CARROTBAT droppers.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1057
Process Discovery

SYSCON has the ability to use Tasklist to list running processes.

T1059.003
Windows Command Shell

SYSCON has the ability to execute commands through cmd on a compromised host.

T1071.002
File Transfer Protocols

SYSCON has the ability to use FTP in C2 communications.

T1082
System Information Discovery

SYSCON has the ability to use Systeminfo to identify system information.

T1204.002
Malicious File

SYSCON has been executed by luring victims to open malicious e-mail attachments.

Groups that use it0

None recorded.

Campaigns1

References2

  1. Unit 42 CARROTBAT January 2020 Open source
    McCabe, A. (2020, January 23). The Fractured Statue Campaign: U.S. Government Agency Targeted in Spear-Phishing Attacks. Retrieved June 2, 2020.
  2. Unit 42 CARROTBAT November 2018 Open source
    Grunzweig, J. and Wilhoit, K. (2018, November 29). The Fractured Block Campaign: CARROTBAT Used to Deliver Malware Targeting Southeast Asia. Retrieved June 2, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.