Executive Summary
BLINDINGCAN is a North Korean government-sponsored remote access Trojan targeting Western European and US defense, engineering, and government sectors. It has been active since at least early 2020 and poses a significant threat due to its data exfiltration and command execution capabilities. The malware's continued use highlights the persistent threat of nation-state cyber operations.
Enhanced Description
BLINDINGCAN is a sophisticated remote access Trojan (RAT) that has been employed by the North Korean government in its cyber operations since at least early 2020. This malware has primarily targeted defense, engineering, and government organizations in Western Europe and the US, highlighting its significance in the realm of nation-state sponsored cyber threats. The use of BLINDINGCAN by North Korean actors underscores the evolving landscape of cyber warfare, where state-sponsored groups leverage malware to infiltrate and gather intelligence from high-value targets. The impact of BLINDINGCAN can be substantial, given its capabilities as a RAT, which typically include remote command execution, data exfiltration, and the ability to install additional malware, thus compromising the integrity and confidentiality of the targeted systems.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the available data is moderate to high, given the malware's documented use by North Korean government-sponsored actors and its targeting of specific sectors. However, analysis gaps exist regarding the full extent of BLINDINGCAN's capabilities, its potential evolution, and the exact scope of its deployment.
BLINDINGCAN is a remote access Trojan that has been used by the North Korean government since at least early 2020 in cyber operations against defense, engineering, and government organizations in Western Europe and the US.(Citation: US-CERT BLINDINGCAN Aug 2020)(Citation: NHS UK BLINDINGCAN Aug 2020)