BLINDINGCAN
MITRE ATT&CK: S0520 View on attack.mitre.org
Aliases: AIRDRY, ZetaNile, BLINDINGCAN
- First seen
- 2020-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:38:38
Targeted industries: defense-and-aerospace government-and-public-sector
Targeted regions: country_code:us country_code:de
Context
BLINDINGCAN is a remote access Trojan that has been used by the North Korean government since at least early 2020 in cyber operations against defense, engineering, and government organizations in Western Europe and the US.
Detection coverage
- 3 YARA rules
- 330 Sigma rules
Malware & tools used
- System Information Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- Web Protocols (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Data from Local System (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Standard Encoding (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Code Signing (attack-pattern)
- File Deletion (attack-pattern)
- Software Packing (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Timestomp (attack-pattern)
- Shared Modules (attack-pattern)
- Malicious File (attack-pattern)
- Rundll32 (attack-pattern)
- Local Storage Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
Used by threat actors
- Lazarus Group (threat-actor)
Detection rules
- MALPEDIA_Win_Blindingcan_Auto (yara-rule)
- SEKOIA_Apt_Lazarus_Blindingcan_Rtti (yara-rule)
- SIGNATURE_BASE_Hvs_APT37_RAT_Loader (yara-rule)
Reports & references
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- blogs.jpcert.or.jp — Blindingcan (report)
- hvs-consulting.de — Lazarus Report (report)
- Kaspersky — 110355 (report)
- virusbulletin.com — Lazarus Campaigns And Backdoors In 2022 2023 (report)
- brandefense.io — Lazarus Apt Group Apt38 (report)
- CISA — Ar20 232A (report)
- Kaspersky — 109490 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Blindingcan (report)
- sentinelone.com — The Blindingcan Rat And Malicious North Korean Activity (report)
- CISA — Ar20 232A (report)
- ESET — Amazon Themed Campaigns Lazarus Netherlands Belgium (report)
- hvs-consulting.de — Threatreport Lazarus (report)
- Mandiant — Dprk Whatsapp Phishing (report)
- Microsoft — Zinc Weaponizing Open Source Software (report)
- MITRE ATT&CK — S0520 (report)
- digital.nhs.uk — Cc 3603 (report)