The Dacls RAT ...now on macOS!

2020-05-05 Objective-see

https://objective-see.com/blog/blog_0x57.html

Thumbnail for The Dacls RAT ...now on macOS!

Objective-See analyzed a macOS variant of the Lazarus-linked Dacls RAT distributed as a TinkaOTP Apple disk image and application bundle. The initial remote infection path was unknown, but the packaging resembled earlier Lazarus activity that used trojanized macOS applications and social engineering. The sample was an ad hoc-signed 64-bit Mach-O app that copied an embedded resource from the bundle into the user's Library directory as a hidden executable named .mina and set execution permissions. The write-up provides code-signing details, hashes, installation behavior, and detection context that help track Lazarus tradecraft on macOS.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 67.43.239.146 2020-05-05 2023-01-18
IPv4 185.62.58.207 2020-05-05 2023-01-18
HASH 4f3367208a1a6eebc890d020eeffb9e… 2020-05-05 2020-05-05
HASH 8bd4b789e325649bafcc23f70bae0d1… 2020-05-05 2020-05-05
HASH 4f3367208a1a6eebc890d020eeffb9e… 2020-05-05 2020-05-05
HASH d2e8bbc6db07e2c468674f829a3991d… 2020-05-05 2020-05-05
HASH 08dd7e9fb1551c8d893fac2193d8c49… 2020-05-05 2020-05-05

Related Reports

« Back