APT trends report Q1 2023

2023-04-27 Kaspersky

https://securelist.com/apt-trends-report-q1-2023/109581/

Thumbnail for APT trends report Q1 2023

DTrack is a backdoor that has been used by Andariel (aka StonedFly and Silent Chollima), a subset of Lazarus, for almost a decade in a wide variety of attacks, including deploying ransomware as well as espionage malware. We observed a Lazarus campaign, active until January 2023, leveraging a backdoored UltraVNC client to deliver an updated BLINDINCAN payload. We have identified ongoing spear-phishing campaigns targeting Middle Eastern countries dating back to July 2021. In our latest private report, we revisited a campaign from 2022 and expanded on the commands the attackers used to deploy DTrack and the accompanying post-exploitation tools and malware (e.g., 3proxy and Yamabot) deployed thereafter.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN ably.com 2023-04-27 2023-04-27

Related Actors

First seen: Jul 2017
Last seen: May 2026

Related Reports

« Back