Hello! My name is Dtrack
2019-09-23 • Kaspersky •
Kaspersky’s Dtrack analysis links the RAT family to Lazarus through code similarities with older malware and activity against India’s financial sector and research centers. The investigation began with ATMDtrack banking malware targeting Indian ATMs and expanded to more than 180 Dtrack samples uncovered through shared code sequences. Droppers stored encrypted payloads in PE overlays, decrypted them at runtime, and used process hollowing to run spying components under system process names. The report details a Lazarus-associated espionage toolset focused on payload concealment, process hollowing, and data collection.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | f84de0a584ae7e02fb0ffe679f96db8d | 2019-09-23 | 2019-09-23 |
| HASH | 3a3bad366916aa3198fd1f76f3c29f24 | 2019-09-23 | 2019-09-23 |
| HASH | 8f360227e7ee415ff509c2e443370e56 | 2019-09-23 | 2019-09-23 |
Related Reports
Shares tag: DTrack • Same author: Kaspersky
Shares tag: DTrack • Same author: Kaspersky
Shares tag: DTrack
Shares tag: DTrack
Shares tag: DTrack
2023-02-02 •
20% Match
#Whitepaper
#NoPineapple
#DTrack
#GREASE
#Zimbra
#T1082
#T1119
#T1070.004
#T1041
#T1560
#T1071.001
#T1083
#T1071
#T1057
#T1053.005
#T1036.005
#T1059
#T1078
#T1190
#T1049
#T1016
#T1018
#T1003.001
#T1021.001
#T1106
#T1090.001
#T1074
#T1553
#T1033
#T1569.002
#T1090.002
#T1012
#T1087.002
#T1114.002
#T1505.003
#T1556
#T1037.005
#T1136
#T1070.007
#T1587.002
Shares tag: DTrack