{
  "type": "malware",
  "spec_version": "2.1",
  "id": "malware--e928333f-f3df-4039-9b8b-556c2add0e42",
  "created": "2021-03-18T16:15:53.977Z",
  "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
  "external_references": [
    {
      "source_name": "mitre-attack",
      "url": "https://attack.mitre.org/software/S0593",
      "external_id": "S0593"
    },
    {
      "source_name": "ECCENTRICBANDWAGON",
      "description": "(Citation: CISA EB Aug 2020)"
    },
    {
      "source_name": "CISA EB Aug 2020",
      "description": "Cybersecurity and Infrastructure Security Agency. (2020, August 26). MAR-10301706-1.v1 - North Korean Remote Access Tool: ECCENTRICBANDWAGON. Retrieved March 18, 2021.",
      "url": "https://us-cert.cisa.gov/ncas/analysis-reports/ar20-239a"
    }
  ],
  "object_marking_refs": [
    "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
  ],
  "modified": "2025-04-25T14:44:59.309Z",
  "name": "ECCENTRICBANDWAGON",
  "description": "[ECCENTRICBANDWAGON](https://attack.mitre.org/software/S0593) is a remote access Trojan (RAT) used by North Korean cyber actors that was first identified in August 2020. It is a reconnaissance tool--with keylogging and screen capture functionality--used for information gathering on compromised systems.(Citation: CISA EB Aug 2020)",
  "is_family": true,
  "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
  "x_mitre_platforms": [
    "Windows"
  ],
  "x_mitre_deprecated": false,
  "x_mitre_domains": [
    "enterprise-attack"
  ],
  "x_mitre_version": "1.0",
  "x_mitre_attack_spec_version": "3.2.0",
  "x_mitre_aliases": [
    "ECCENTRICBANDWAGON"
  ]
}