DTrack activity targeting Europe and Latin America
2022-11-15 • Kaspersky •
https://securelist.com/dtrack-targeting-europe-latin-america/107798/
Kaspersky reported that Lazarus continued using the DTrack backdoor three years after its 2019 discovery, with telemetry showing activity in Europe, Latin America, the Middle East, Asia, and the United States. DTrack supports file upload, download, execution, and deletion, and its toolset has included a keylogger, screenshot module, and system information collector that can support lateral movement and data theft. Recent samples used multi-stage unpacking and decryption, modified RC4/RC5/RC6-like algorithms, API hashing, process hollowing into explorer.exe, and a reduced set of three C2 servers. The reported victimology included education, chemical manufacturing, government research and policy institutes, IT services, utilities, and telecommunications, showing Lazarus continued to adapt an older backdoor for varied financial and strategic operations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 67f4dad1a94ed8a47283c2c0c05a7594 | 2022-11-15 | 2023-02-10 |
| HASH | 1a74c8d8b74ca2411c1d3d22373a6769 | 2022-11-15 | 2023-02-10 |
| DOMAIN | purplebear.com | 2022-11-15 | 2022-11-15 |
| IPv4 | 52.128.23.153 | 2022-11-15 | 2022-11-15 |
| IPv4 | 64.190.63.111 | 2022-11-15 | 2022-11-15 |
| IPv4 | 58.158.177.102 | 2022-11-15 | 2022-11-15 |
| DOMAIN | purewatertokyo.com | 2021-03-22 | 2022-11-15 |
| DOMAIN | salmonrabbit.com | 2021-03-22 | 2022-11-15 |
| DOMAIN | pinkgoat.com | 2021-03-22 | 2022-11-15 |