ECCENTRICBANDWAGON is a Windows malware family publicly associated with North Korean government cyber operations, specifically activity attributed to the BeagleBoyz subgroup within the broader HIDDEN COBRA/Lazarus/APT38 ecosystem. It has been documented in U.S. government malware analysis reporting tied to financially motivated campaigns targeting the banking sector, including operations related to ATM cash-out activity.
The malware supports user surveillance and collection functions including screenshot capture and keylogging. Captured screenshots and keystrokes are stored locally in temporary directories prior to further handling, indicating a staging workflow on compromised hosts. ECCENTRICBANDWAGON also includes cleanup capability, including deletion of malware-generated log files, consistent with anti-forensic tradecraft and operational hygiene.
Observed behavior indicates use on Windows systems and local storage of collected artifacts in temporary locations. The combination of keystroke capture, screen capture, local staging, and artifact deletion makes ECCENTRICBANDWAGON suitable for credential collection and post-compromise monitoring in targeted intrusions. Public reporting links it to North Korea-aligned financially motivated operations rather than broad indiscriminate malware distribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...three Malware Analysis Reports (MAR) were released as well and they are: MAR-10301706.-1.v1 - 4 samples (ECCENTRICBANDWAGON)
...three Malware Analysis Reports (MAR) were released as well and they are: MAR-10301706.-1.v1 - 4 samples (ECCENTRICBANDWAGON)
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
Examples throughout the content include deleting tools, logs, malware-related files, staged archives, screenshots, temporary files, and exfiltrated data 'to cover their tracks,' 'reduce their footprint,' 'remove traces of activity,' or as part of 'post-intrusion cleanup.'
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Minor Software changes: ... ECCENTRICBANDWAGON
Backdoor malware that deletes its generated log files.
Backdoor malware that captures screenshots and stores them locally.
Surveillance malware that stores keystrokes and screenshots in temporary directories before exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.