The Dacls RAT ...now on macOS!
2020-05-05 • Objective-see •
Objective-See analyzed a macOS variant of the Lazarus-linked Dacls RAT distributed as a TinkaOTP Apple disk image and application bundle. The initial remote infection path was unknown, but the packaging resembled earlier Lazarus activity that used trojanized macOS applications and social engineering. The sample was an ad hoc-signed 64-bit Mach-O app that copied an embedded resource from the bundle into the user's Library directory as a hidden executable named .mina and set execution permissions. The write-up provides code-signing details, hashes, installation behavior, and detection context that help track Lazarus tradecraft on macOS.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 67.43.239.146 | 2020-05-05 | 2023-01-18 |
| IPv4 | 185.62.58.207 | 2020-05-05 | 2023-01-18 |
| HASH | 4f3367208a1a6eebc890d020eeffb9e… | 2020-05-05 | 2020-05-05 |
| HASH | 8bd4b789e325649bafcc23f70bae0d1… | 2020-05-05 | 2020-05-05 |
| HASH | 4f3367208a1a6eebc890d020eeffb9e… | 2020-05-05 | 2020-05-05 |
| HASH | d2e8bbc6db07e2c468674f829a3991d… | 2020-05-05 | 2020-05-05 |
| HASH | 08dd7e9fb1551c8d893fac2193d8c49… | 2020-05-05 | 2020-05-05 |