ATT&CKSoftwareECCENTRICBANDWAGON

ECCENTRICBANDWAGON

S0593

Malware.View on attack.mitre.org

About this malware

ECCENTRICBANDWAGON is a remote access Trojan (RAT) used by North Korean cyber actors that was first identified in August 2020. It is a reconnaissance tool--with keylogging and screen capture functionality--used for information gathering on compromised systems.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1027
Obfuscated Files or Information

ECCENTRICBANDWAGON has encrypted strings with RC4.

T1056.001
Keylogging

ECCENTRICBANDWAGON can capture and store keystrokes.

T1059.003
Windows Command Shell

ECCENTRICBANDWAGON can use cmd to execute commands on a victim’s machine.

T1070.004
File Deletion

ECCENTRICBANDWAGON can delete log files generated from the malware stored at C:\windows\temp\tmp0207.

T1074.001
Local Data Staging

ECCENTRICBANDWAGON has stored keystrokes and screenshots within the %temp%\GoogleChrome, %temp%\Downloads, and %temp%\TrendMicroUpdate directories.

T1113
Screen Capture

ECCENTRICBANDWAGON can capture screenshots and store them locally.

Groups that use it2

Campaigns0

None recorded.

References1

  1. CISA EB Aug 2020 Open source
    Cybersecurity and Infrastructure Security Agency. (2020, August 26). MAR-10301706-1.v1 - North Korean Remote Access Tool: ECCENTRICBANDWAGON. Retrieved March 18, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.