Hello! My name is Dtrack

2019-09-23 Kaspersky

https://securelist.com/my-name-is-dtrack/93338/

Thumbnail for Hello! My name is Dtrack

Kaspersky’s Dtrack analysis links the RAT family to Lazarus through code similarities with older malware and activity against India’s financial sector and research centers. The investigation began with ATMDtrack banking malware targeting Indian ATMs and expanded to more than 180 Dtrack samples uncovered through shared code sequences. Droppers stored encrypted payloads in PE overlays, decrypted them at runtime, and used process hollowing to run spying components under system process names. The report details a Lazarus-associated espionage toolset focused on payload concealment, process hollowing, and data collection.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f84de0a584ae7e02fb0ffe679f96db8d 2019-09-23 2019-09-23
HASH 3a3bad366916aa3198fd1f76f3c29f24 2019-09-23 2019-09-23
HASH 8f360227e7ee415ff509c2e443370e56 2019-09-23 2019-09-23

Related Reports

« Back