BLINDINGCAN is a Windows remote access trojan associated with North Korean state-sponsored activity, particularly Lazarus Group and the broader HIDDEN COBRA tracking umbrella. It has been used in espionage-focused intrusions against defense, aerospace, and government-contractor targets, including organizations in Europe and the United States, with collection objectives tied to military and energy technologies.
BLINDINGCAN has been delivered through phishing campaigns using malicious Microsoft Office documents themed as job postings or contractor-related material. Reported lure documents attempted to exploit CVE-2017-0199 to retrieve additional payloads, after which the malware chain installed and executed BLINDINGCAN components. Variants have used layered obfuscation and unpacking, including XOR decoding of embedded content, AES decryption of configuration or embedded DLLs, and RC4-encrypted strings or communications. The malware has also attempted to evade detection by masquerading payloads with legitimate-looking names and by modifying file or directory timestamps.
As a RAT, BLINDINGCAN supports broad remote control of compromised hosts. Documented capabilities include collecting host and network configuration details such as system name, operating system version, processor or platform information, local IP address, and MAC address; sending user and system information to command-and-control infrastructure via HTTP POST; uploading files from victim machines; creating and terminating processes; enumerating disks and directories; searching, reading, writing, moving, and executing files; and self-updating or self-deleting to remove artifacts from infected systems. Reporting also attributes keylogging and clipboard monitoring to the campaign associated with BLINDINGCAN. Command-and-control traffic has been observed encoded with Base64 and encrypted with RC4.
BLINDINGCAN is part of a long-running Lazarus malware ecosystem that includes other espionage, financial, and disruptive tooling. Its tradecraft emphasizes stealth, persistence, reconnaissance, and exfiltration in support of intelligence collection operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The malicious documents themselves, upon launch, attempt to exploit CVE-2017-0199. This particular flaw allows for remote code execution via maliciously crafted documents. More specifically, CVE-2017-0199 is a result of the flawed processing of RTF files and elements by way of a potent combination of object links and HTA payloads. | Most recently, this has culminated in the release of MAR (Malware Analysis Report) AR20-232A, which covers activities associated with the BLINDINGCAN RAT.
Lazarus’ Bring Your Own Vulnerable Driver (BYOVD) technique to deploy BLINDINGCAN
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Related Malware: AppleJeus BADCALL Bankshot BLINDINGCAN Cryptoistic Dtrack KEYMARBLE KiloAlfa SierraAlfa ThreatNeedle Torisma WannaCry
Malware and Tools · Blindingcan : A remote access Trojan associated with Lazarus
"Tools Used In Recent Campaigns... Blindingcan remote access Trojan"
33 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Command and Scripting Interpreter: PowerShell [T1059]
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
attempted to lure victims into enabling malicious macros within email attachments... prompted victims to accept macros... Word documents containing malicious macros.
The malicious documents themselves, upon launch, attempt to exploit CVE-2017-0199. This particular flaw allows for remote code execution via maliciously crafted documents.
has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails... has required user execution of a malicious MSI installer... has been executed through user installation of an executable disguised as a flash installer.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
It contains the following built-in functions ... Get and modify file or directory timestamps
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
In this stage, the malware will pull local network data, system name, OS version details, processor/platform details and MAC address details, and then push this data to the C2.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
The HTTP POST body contains four parameters of Base64 encoded data ... The datagram is encrypted with a combination of RC4 and differential XOR.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
ADVSTORESHELL C2 traffic is encrypted, then encoded with Base64 encoding. APT19 HTTP malware variant used Base64 to encode communications to the C2 server. APT33 has used base64 to encode command and control traffic.
130 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
75 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as malware used by Lazarus Group in the example APT profile.
Named malware/tool listed in an ESET APT activity report; no further detail is provided in the content.
Lazarus와 관련된 원격 접근 트로이 목마로, 원격 제어와 후속 침해 활동에 사용된다.
Remote access Trojan associated with Lazarus, used for penetration and credential collection in campaigns tied to Medusa ransomware activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.