SYSCON

MITRE ATT&CK: S0464 View on attack.mitre.org

Aliases: SYSCON

First seen
2017-01-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 14:51:39

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:kr country_code:us

Context

SYSCON is a backdoor that has been in use since at least 2017 and has been associated with campaigns involving North Korean themes. SYSCON has been delivered by the CARROTBALL and CARROTBAT droppers.

Detection coverage

  • 1 YARA rules
  • 91 Sigma rules

Malware & tools used

  • Windows Command Shell (attack-pattern)
  • Malicious File (attack-pattern)
  • Process Discovery (attack-pattern)
  • File Transfer Protocols (attack-pattern)
  • System Information Discovery (attack-pattern)

Used by threat actors

  • Operation Honeybee (campaign)

Detection rules

  • MALPEDIA_Win_Syscon_Auto (yara-rule)

Reports & references

  • Palo Alto Unit 42 — The Fractured Statue Campaign U S Government Targeted In Spear Phishing Attacks (report)
  • Palo Alto Unit 42 — Unit42 The Fractured Block Campaign Carrotbat Malware Used To Deliver Malware Targeting Southeast Asia (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Syscon (report)
  • McAfee — Mcafee Uncovers Operation Honeybee Malicious Document Campaign Targeting Humanitarian Aid Groups (report)
  • Trend Micro — Syscon Backdoor Uses Ftp As A Cc Channel (report)
  • MITRE ATT&CK — S0464 (report)

External references