S0520: BLINDINGCAN
BLINDINGCAN is a remote access Trojan that has been used by the North Korean government since at least early 2020 in cyber operations against defense, engineering, and government organizations in Western Europe and the US.CitationUS-CERT BLINDINGCAN Aug 2020CitationNHS UK BLINDINGCAN Aug 2020
Security context for executives and security teams
BLINDINGCAN matters because ATT&CK describes it as a Windows remote access Trojan used in operations against defense, engineering, and government organizations in Western Europe and the US. For leaders, the practical issue is not just “malware on an endpoint”; it is the potential for remote control, discovery of sensitive systems and files, tool transfer, command-and-control over web protocols, and data exfiltration through the same channel.
Executive priority
Prioritize this as a resilience and evidence question for Windows environments that hold sensitive government, defense, engineering, or regulated data. Executives should ask whether the organization can prove coverage across phishing-delivered malicious files, suspicious Windows command shell and rundll32 activity, encoded or encrypted C2 over web traffic, local data discovery, tool ingress, and exfiltration over C2. The ATT&CK object has no official detection text, so assurance should come from validated telemetry and tested response playbooks rather than assumptions.
Technical view
SOC and IR teams should validate detection and investigation coverage around the related ATT&CK behaviors: spearphishing attachment and malicious file execution, Windows command shell execution, rundll32 and shared module loading, obfuscated/packed or encoded files, code signing abuse, system/network/storage/file discovery, ingress tool transfer, web-protocol C2, standard encoding, symmetric cryptography, exfiltration over C2, file deletion, and timestomping. Because the software platform is Windows, prioritize Windows endpoint, email, identity, proxy, DNS, and network evidence that can connect initial execution to discovery, C2, and data movement.
Likely telemetry
- Email security logs and attachment detonation or analysis results for targeted malicious attachments
- Windows process creation telemetry for cmd.exe, rundll32.exe, DLL/shared module loading, and unusual parent-child process chains
- Endpoint file metadata, creation/deletion events, timestamp anomalies, packed or encoded file indicators, and code-signing details
- Command-line and script execution records showing discovery of system, network, storage, files, and directories
- Proxy, firewall, DNS, and TLS/web traffic metadata for unusual outbound web-protocol C2 patterns
Detection direction
- Build correlations across phases rather than relying on a single malware signature: phishing or malicious file execution followed by cmd/rundll32 activity, discovery commands, outbound web traffic, and file staging or exfiltration indicators.
- Tune for legitimate administrative overlap. Command shell, rundll32, encoded data, and web protocols are common in normal environments, so detections should use context such as unusual parent process, user, host role, destination, file path, module, signing status, and timing.
- Account for stealth behaviors in triage: software packing, encoded files, matched legitimate names or locations, file deletion, and timestomping can reduce the value of simple hash, filename, or timestamp-based searches.
- Use relationship context to inform threat hunting for Lazarus Group-associated tradecraft, while avoiding attribution conclusions unless local evidence supports them.
Mitigation priorities
- Reduce initial execution risk through attachment controls, user reporting workflows, and safe handling of high-risk file types associated with spearphishing attachments and malicious files.
- Harden and monitor Windows execution paths, especially command shell, rundll32, shared module loading, and unsigned or suspiciously signed binaries.
- Ensure egress controls and monitoring cover outbound web protocols, encoded or encrypted C2-like traffic, and external tool transfer patterns.
- Protect sensitive local data with least privilege and segmentation so host-level discovery does not automatically expose high-value files or systems.
- Prepare IR procedures for evidence preservation where file deletion and timestomping are possible, including rapid endpoint isolation and collection of volatile and filesystem metadata.
Additional notes and limits
The supplied ATT&CK record identifies BLINDINGCAN as a Windows remote access Trojan and provides relationships to techniques spanning initial access, execution, discovery, defense evasion/impairment, command and control, collection, and exfiltration. The relationship to Lazarus Group and the official description support North Korea-related context, but local investigation should not infer attribution from technique matches alone.
MITRE provides no official detection text for this object, no aliases, no labels, and no object-level tactics. Several related techniques list platforms beyond Windows, but the BLINDINGCAN software platform supplied here is Windows; platform-specific conclusions should therefore be limited to Windows unless separate evidence supports broader scope.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
BLINDINGCAN
BLINDINGCAN is a remote access Trojan that has been used by the North Korean government since at least early 2020 in cyber operations against defense, engineering, and government organizations in Western Europe and the US.CitationUS-CERT BLINDINGCAN Aug 2020CitationNHS UK BLINDINGCAN Aug 2020
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
