DTrack activity targeting Europe and Latin America

2022-11-15 Kaspersky

https://securelist.com/dtrack-targeting-europe-latin-america/107798/

Thumbnail for DTrack activity targeting Europe and Latin America

Kaspersky reported that Lazarus continued using the DTrack backdoor three years after its 2019 discovery, with telemetry showing activity in Europe, Latin America, the Middle East, Asia, and the United States. DTrack supports file upload, download, execution, and deletion, and its toolset has included a keylogger, screenshot module, and system information collector that can support lateral movement and data theft. Recent samples used multi-stage unpacking and decryption, modified RC4/RC5/RC6-like algorithms, API hashing, process hollowing into explorer.exe, and a reduced set of three C2 servers. The reported victimology included education, chemical manufacturing, government research and policy institutes, IT services, utilities, and telecommunications, showing Lazarus continued to adapt an older backdoor for varied financial and strategic operations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 67f4dad1a94ed8a47283c2c0c05a7594 2022-11-15 2023-02-10
HASH 1a74c8d8b74ca2411c1d3d22373a6769 2022-11-15 2023-02-10
DOMAIN purplebear.com 2022-11-15 2022-11-15
IPv4 52.128.23.153 2022-11-15 2022-11-15
IPv4 64.190.63.111 2022-11-15 2022-11-15
IPv4 58.158.177.102 2022-11-15 2022-11-15
DOMAIN purewatertokyo.com 2021-03-22 2022-11-15
DOMAIN salmonrabbit.com 2021-03-22 2022-11-15
DOMAIN pinkgoat.com 2021-03-22 2022-11-15

Related Reports

« Back